Skip to content

SonicWall

A firewall and security vendor focused on small and mid-sized businesses, offering subscription-based appliances and a growing cloud-native and MSSP business.

Visit Website ↗
47/100Emerging / Unranked

Overview

SonicWall targets the small-business, branch-office, and managed-security-service-provider (MSSP) segments with firewall appliances (its TZ and NSa lines), wireless security, and endpoint/email add-ons, priced and packaged for organizations that lack a dedicated large security team. In November 2024 it launched the TZ80, a subscription-priced firewall aimed squarely at SMB, branch, and SOHO deployments, continuing its appliance-plus-subscription business model.

The company reports strong growth in its cloud-native and managed-security-service channel — citing 700% year-over-year growth in its cloud-native business and double-digit growth in MSSP-delivered services through 2024 — as it tries to shift its revenue mix away from pure hardware sales toward recurring cloud and services revenue.

SonicWall’s SMB-focused VPN and firewall products have been a recurring target for ransomware affiliates: SonicWall SSL-VPN vulnerabilities have been repeatedly implicated in ransomware intrusion campaigns (including activity attributed to Akira ransomware affiliates) through 2024 and 2025, a pattern consistent with the broader industry problem of edge VPN devices being high-value initial-access targets, but a particular concern given SonicWall’s SMB customer base often has less mature patch-management operations than large enterprises.

Innovation Matrix Assessment

Innovation Velocity 5/10

The November 2024 TZ80 launch and reported 700% cloud-native growth show continued investment, though releases are incremental within an established appliance product line.

Operational Value 6/10

Good price-performance and manageability for resource-constrained SMB IT teams and MSSPs, which is the segment it's purpose-built for.

Market Momentum 5/10

Reported double-digit MSSP growth and 700% cloud-native growth are notable, but SonicWall has less headline funding/analyst momentum than cloud-native SASE peers and remains PE-owned under Francisco Partners.

Category Disruption 3/10

A traditional appliance firewall vendor extending into subscription and cloud services rather than pursuing a structurally different security model.

Real-World Efficacy 4/10

SonicWall SSL-VPN and firewall vulnerabilities have been repeatedly exploited in ransomware intrusion campaigns (including Akira-affiliate activity) through 2024-2025, a pattern that is especially concerning given its SMB customer base often has less mature patch-management capacity.

Enduring Relevance 5/10

The SMB/MSSP firewall market remains a real and persistent need, but SonicWall is not positioned at the innovation frontier of network security architecture.

Why CISOs Should Care

For resource-constrained SMB IT teams or MSSPs managing many small customer networks, SonicWall's appliance-plus-subscription model is accessible and manageable, but the recurring pattern of exploited SSL-VPN vulnerabilities means patch cadence has to be actively enforced, not assumed.

What Makes It Different

Not architecturally distinct from traditional appliance firewalls — its differentiation is pricing, packaging, and channel focus (SMB and MSSP) rather than a new security model.

The Matrix Verdict

47/100 — EMERGING / UNRANKED

A steady, accessible SMB-focused firewall vendor whose repeated VPN exploitation by ransomware affiliates is a genuine and recurring efficacy concern, particularly given its less security-mature customer base. A Cautionary, Solid-at-Best Performer.

Editorial Note: Claims vs. Verified Findings

The TZ80 launch and reported growth percentages are vendor-published (SonicWall/MSSP Alert). Ransomware exploitation of SonicWall SSL-VPN products in 2024-2025 is independently reported by multiple threat-intelligence and incident-response firms tracking Akira-affiliate activity, though specific attribution figures should be checked against the latest CISA/vendor advisories at time of publication.

Sources