China has put one of America’s biggest cybersecurity companies under the microscope, adding network security software to the growing list of US technologies caught in the escalating Beijing-Washington standoff.
The Cyberspace Administration of China said Thursday that its Cybersecurity Review Office had begun a review of products sold in China by Palo Alto Networks, citing the need to protect critical information infrastructure, prevent cybersecurity risks and safeguard national security.
The regulator did not identify the products being examined, disclose specific vulnerabilities or say what restrictions the company could face.
“We maintain the highest standards of business conduct and security practices and ethics across our global operations. At this time, there is no impact to our ability to support customers or deliver our products and services in the region,” said Palo Alto Networks in a statement to The Register.
Timing raises questions
The review comes one day after China announced restrictions on a group of US companies and tightened controls involving the drone supply chain, describing those moves as responses to US restrictions on Chinese businesses.
China did not say the Palo Alto Networks investigation was connected to those measures. Still, the timing puts the review against a backdrop of worsening technology and trade tensions.
Washington and Beijing have spent months trying to preserve an uneasy trade truce while reducing their dependence on each other’s technology. Cybersecurity is particularly sensitive because security products are embedded directly into the networks they are supposed to protect.
Chinese officials have defended the review as a national security measure rather than retaliation. Zhou Mi, a researcher at the Chinese Academy of International Trade and Economic Cooperation, said foreign technology used in critical infrastructure can warrant regulatory scrutiny.
The Micron warning
The biggest concern for Palo Alto Networks is what happened to Micron Technology.
China launched a cybersecurity review of the US memory-chip maker in 2023 and later said its products posed security risks to critical information infrastructure. Operators were subsequently barred from purchasing Micron products.
The Register reported that Micron eventually stopped selling its datacenter and server products in China, costing the company billions in annual revenue. That precedent gives the Palo Alto review greater commercial significance even though the cybersecurity company does not separately disclose its China revenue.
SCMP cited Shanghai export-control lawyer Shi Shenchang as saying Palo Alto Networks could face a similar restriction if it fails the review, potentially affecting sectors such as finance, energy, telecommunications and transportation.
What it means for cybersecurity
The immediate impact appears limited: Palo Alto says it can continue supporting customers and delivering products in the region.
The larger risk is strategic. Firewalls, cloud security and threat-detection systems sit deep inside corporate and government networks, making foreign suppliers particularly sensitive targets as China and the US increasingly treat technology as a national-security issue.
The review could also accelerate demand for domestic alternatives. Chinese companies such as Huawei and H3C already offer products that overlap with Palo Alto Networks’ security portfolio, according to The Register.
For global cybersecurity vendors, geopolitical risk is no longer confined to chips, telecom equipment or artificial intelligence. Security software itself is becoming part of the contest. That creates a dilemma for companies operating globally. Access to the Chinese market may remain commercially valuable, but products that sit closest to a country’s critical infrastructure can also become the easiest targets when political relations deteriorate.
Read more: As Palo Alto Networks faces scrutiny in China, learn about a recent firewall zero-day exploited in active attacks.





