Managed Firewall for Business
Most businesses have a firewall. Rather fewer have one that anybody looks at, updates or reads the logs from — which is the difference between a firewall and a managed one.
Request a quoteA firewall nobody watches is a box with a light on
The hardware is not usually the problem. Almost every business has something between its network and the internet, often supplied with the broadband router, and it does block the obvious. The problem is that firmware goes years without updating, rules are added for a reason that has long since ended and never removed, and the logs — which are the only record of somebody trying — are never read by anybody.
Managed means those things happen: firmware kept current, rules reviewed rather than accumulated, alerts going somewhere a person sees them, and a monthly report you can hand to whoever asks. That last part is more valuable than it sounds, because most of the pressure to improve security now comes from customers and insurers asking questions rather than from an actual incident, and "yes, here is the report" is a far better answer than "we think so."
It is worth being clear about what a firewall does not cover. It does not stop somebody clicking a link in an email, it does not protect a laptop being used on a home connection, and it does not help if an attacker already has a valid password. Those need email filtering, endpoint protection and multi-factor authentication respectively. A firewall is one control among several, and anyone selling it as the answer to ransomware is overselling it.
What managed adds
Firmware kept current
Patched on a schedule, not when somebody notices. Unpatched firewalls are a routine finding.
Rules reviewed
Rules opened for a project that ended three years ago get closed, rather than accumulating quietly.
Alerts a person sees
Monitoring by people rather than a log file nobody opens. An alert nobody reads is not detection.
Reporting you can hand over
A monthly report that answers the security questionnaire without a week of guessing.
Content and application control
Blocking categories and applications where that is genuinely wanted, configured rather than assumed.
Secure remote access
Proper VPN access for home and travelling staff, rather than ports opened to the internet and forgotten.
Who we work with
We are independent of any single network or vendor, so the recommendation follows the requirement.
Network & security
We build on the platform that fits the requirement rather than the one we happen to stock.
Fortinet
Palo Alto
Ubiquiti
Forcepoint
Network and vendor names and logos are the trademarks of their respective owners, shown to describe the services SCG Solutions supplies.
What it does not cover
- Somebody clicking a link in an email — that needs email filtering and training
- A laptop on a home broadband connection, outside your network entirely
- An attacker who already has a valid username and password — that needs MFA
- Data taken by somebody who legitimately has access to it
- A device already compromised before it arrived on your network
- Anyone selling a firewall as the complete answer to ransomware is overselling it
Managed Firewall for Business — Common Questions
We already have a firewall — why would we manage it?
Because the hardware is rarely the weak part. The common findings are firmware years out of date, rules opened for a project that ended long ago and never closed, and logs nobody has read. Managing it means those things happen on a schedule rather than when somebody remembers, which is the actual difference in protection.
Will a firewall stop ransomware?
Not on its own, and we would rather say so. Most ransomware arrives through email or stolen credentials, neither of which a firewall sees. It is one control among several — you also need email filtering, endpoint protection, multi-factor authentication and backups you have tested. Anyone selling a firewall as the whole answer is overselling it.
Does it protect staff working from home?
Only when they connect back through it. A laptop on a home broadband connection is outside your network, which is why endpoint protection on the device matters more than the office firewall for remote workers. Where staff do need access to systems on the office network, a properly configured VPN is the right route.
Will it slow the internet connection down?
A correctly sized device will not. An undersized one will, particularly with deep inspection turned on, and that is a genuine and common mistake — a firewall specified for a fifty-megabit line will not cope with a gigabit one. Sizing is worth getting right at the outset rather than diagnosing later.
Do we get anything we can show a customer?
Yes — a monthly report covering what was blocked, what was updated and what changed. Most of the current pressure to improve security comes from customer and insurer questionnaires rather than incidents, and being able to answer with a document rather than an assurance is usually the practical value.
Can you manage the firewall we already have?
Often, depending on make and age. Where the existing device is still supported and appropriately sized, managing it is cheaper than replacing it and we would recommend that. Where it is out of support, no longer receiving firmware updates, or too small for the connection, replacing it is the honest answer.
More IT & Cloud Services
When was the firmware last updated?
If nobody knows, that is the answer. A short review tells you what the current device does, what its rules actually permit and whether managing it is worth the money — including when it is not.
