Powering the AI Enterprise with New Software Firewall Capabilities

Jan 21, 2026
4 minutes

Innovation is at risk when fragmented security spans complex multicloud environments. It’s one of the many reasons why we are excited to announce the addition of significant new capabilities to our Hybrid Mesh Firewall (HMF) platform.

We have addressed three key areas designed to transform security from a bottleneck into a business accelerator: securing the AI enterprise and modern architectures, optimizing resilience with intelligent operations, and accelerating time-to-value with frictionless deployment. Each of these three areas is designed to secure innovation quickly and easily.

Furthermore, these new capabilities address the evolving requirements of scaling modern cloud workloads and AI applications in distributed cloud environments, which comprise on-premises data centers, private clouds and public cloud environments. No matter where applications are hosted, our unified HMF platform synchronizes security everywhere so hybrid infrastructures keep ticking.

Securing the AI Enterprise and Modern Architectures

With the rapid adoption of AI, securing AI infrastructure is paramount. Traditional firewalls create visibility gaps in encrypted east-west traffic, leaving high-value models exposed. Our solution closes these gaps by extending a single, consistent Layer 7 security policy to every corner of your environment—from AI factories to the service mesh.

  • Leverage uncompromised AI security. With Prisma® AIRS™ on NVIDIA BlueField-3 DPUs, you can embed AI-driven Layer 7 protection directly into the computing data plane to secure the entire AI lifecycle, from massive data ingestion to training and inference, without adding the latency that slows down models.
  • Secure microservices at runtime. Coming in February, you will be able to detect and block attacks inside encrypted microservices traffic with native Istio runtime protection, gaining visibility into an area where traditional tools are effectively blind.
  • Get Zero Trust at the workload level. Our expanded Layer 7 microperimeter allows you to establish a lightweight "secure microperimeter" on individual Windows and Linux workloads to prevent lateral movement even if the network perimeter is breached.

Optimizing Resilience with Intelligent Operations

Our HMF unifies security across your entire cybersecurity estate, shifting operations from a reactive "break/fix" model to a proactive "predict and prevent" posture. By applying unified intelligence across the software-defined estate, we enable you to maintain resilience without the manual overhead.

  • Make the most of end-to-end, policy-aware visibility. With Cloud Tracer, you can correlate network and security insights across AWS, Azure, Google Cloud and on-premises environments, reducing mean time to resolution (MTTR) for connectivity and security roadblocks from hours to minutes.
  • Protect users with proactive health management. You will be able to continuously monitor health and predict potential performance bottlenecks using AIOps for Software Firewalls coming in February, receiving actionable recommendations to resolve issues before users are impacted.

Accelerating Time-to-Value with Frictionless Deployment

Removing operational barriers that stifle innovation starts with ensuring our customers are nimble. Legacy firewall deployments often force a trade-off between speed and security, but our HMF platform delivers new agility required to innovate safely by reducing approval cycles for new deployments, ensuring immediate security for GenAI applications, and unifying policy enforcement with a single click. These new enhancements can greatly simplify how you deploy and manage enforcement points.

  • Launch cloud firewalls in minutes. With the enhanced Strata Cloud Manager onboarding, you can deploy cloud-native enforcement points with fewer than half the steps previously required, eliminating the intrusive IAM roles that typically delay approval cycles.
  • Upgrade firewall protections seamlessly. Our upcoming Prisma AIRS migration support enables you to upgrade from virtual firewall appliances to advanced software firewalls without disruption, ensuring your GenAI applications are secured immediately.
  • Activate instant, consistent protection. New, centralized feature activation will reduce the effort to enable advanced services like DLP and AIOps across your entire estate, removing the need for tedious manual configurations.

Ready to Experience a Leading Network Security Platform?

This launch is about more than just new features. By delivering frictionless deployment, uncompromised protection across your entire environment and unified intelligent operations, we enable you to secure innovation quickly and easily.

If you are unsure where to begin or which blind spots might already exist in your environment, we invite you to evaluate your posture with a free CLARA assessment. This data-driven analysis will identify your specific security gaps and risks, providing a clear roadmap to the resilient, Zero Trust foundation your business needs to innovate without compromise.


Subscribe to Network Security Blogs!

Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more.