Egress is part of the cloud security boundary

Inbound rules get attention because that is where attacks appear to come from. Outbound is where the consequence happens.

Data leaving, commands arriving, tools being downloaded. A default-allow egress policy means a compromised workload has the whole internet available. It is one of the highest-value controls to add and one of the most disruptive to retrofit, which is why it is worth deciding early.

More on Cloud resilience