# Infographic | Who has the Strongest Security Track Record?

## When Networks Are Under Attack

### Who Has the Strongest Security Track Record?

| Vendor      | Malware Block Rate | Zero + 1 Day Attacks | Number of Exploited Firewall Operating System Vulnerabilities | Percent Prevented |
|-------------|---------------------|----------------------|------------------------------------------------|------------------|
| Check Point | 62.7%               |                      |                        | 62.7%            |
| Zscaler     | 67.1%               |                      |                        | 72.5%            |
| Fortinet    | 87.7%               |                      |                        | 42.6%            |
| Cisco       | 90.9%               |                      |                        | 91.6%            |
| Palo Alto   | 99.9%               |                      |                        | 94.6%            |

### Critical Exploits Blocked

| Vendor      | Percent Blocked |
|-------------|------------------|
| Check Point | 98.0%            |

## Who is Miercom?

30 years of industry-leading testing, certification, and rigorous validation of security & networking performance.

### Measuring What Matters

#### Which Vendors Excel at Real-World Threat Prevention?

This comprehensive study pulled in insights from the aforementioned data bases and tools, while following the process outlined to the right.

**Capabilities used by firewalls under test:**  
• Anti-virus  
• URL filtering  
• Anti-phishing  
• Application filtering  
• Intrusion prevention  
• Anti-malware  
• Sandboxing

### The First 24 Hours are Critical

This is the most important time to block Malware, Phishing, and Ransomware, before they spread quickly throughout the network — causing greater damage and downtime.  
Zero + 1 Day Malware (one day past Zero-Day discovery) is newly captured malware in the wild within the first 24 hours of discovery. These are far less likely to be known by any vendor’s signature detection mechanisms. Check Point had only 1 vulnerability vs. 10X–25X more for the other vendors.

#### Least Vulnerabilities = Highest Product Integrity

| Vendor      | Number of KEVs |
|-------------|----------------|
| Check Point | 1 KEV          |
| Cisco       | 25 KEVs        |
| Fortinet    | 30 KEVs        |
| Palo Alto   | 13 KEVs        |

### AI-Powered Cyber Security Platform Assessment

#### An Expanded Evaluation:
See head-to-head comparisons of the top Cyber Security Platforms and their Admin User Experience (UX).

### Intrusion Prevention

How well each vendor prevents High & Critical-severity vulnerabilities & exposures that require immediate attention or remediation (CVSS Score 7-10).

#### For IPS assessments, Miercom uses BreakingPoint - a leading cybersecurity and network testing platform that emulates real-world traffic and security threats.

| Vendor             | Product            | Version |
|--------------------|-------------------|---------|
| Check Point        | Quantum           | R82     |
| Cisco Systems      | FirePower         | 7.6.0   |
| Fortinet           | TDFortiGate       | 11.2.3  |
| Palo Alto Networks | PAN-OS            | 8.1.1   |
| Zscaler            | ZIA               | 1.0.0   |

### When Hackers Target Firewalls

The results are telling: CISA's official exploit tracking reveals vendors' product integrity.

#### The Hidden Costs of Firewall Weaknesses

Critical vulnerabilities in firewall operating systems cause:
- Emergency patches  
- Business disruption  
- Compromised networks  
- Security team overtime

*As of Nov 10, 2025*  
CISA: Cybersecurity & Infrastructure Security Agency  
KEV: Known Exploited Vulnerabilities

[View the full assessment here.](https://www.checkpoint.com/2025-miercom-firewall-report/)  
[View the AI-powered Cyber Security Platform report here.](https://engage.checkpoint.com/2025-miercom-ai-powered-cyber-security-platform)
