Overly permissive rules
Any-to-any rules, broad address ranges and wide-open service definitions that allow far more traffic than the business actually needs.
Years of quick fixes, temporary exceptions and forgotten rules leave most firewalls allowing far more than anyone intended. We review your rule base and configuration line by line and tell you, in plain English, exactly what to tighten.
A firewall is only as strong as its rules, and rules pile up. A port opened for a supplier three years ago, an "any" rule added during an outage, objects pointing at servers that no longer exist.
None of it looks dangerous on its own, and nothing alerts you to it. But together it widens the paths into your network and between its parts, often in ways nobody on the team realises. A firewall rules review finds that drift, explains what each problem allows, and gives you a clean, prioritised list of changes.
It is a configuration review, carried out from an export of your settings, so there is nothing to install, no access to arrange and no risk to your live network.
Any-to-any rules, broad address ranges and wide-open service definitions that allow far more traffic than the business actually needs.
Rules that never match, duplicate others or point at retired systems. They add complexity, hide mistakes and make every future change riskier.
Management interfaces, remote desktop and other high-risk services reachable from the internet or from zones that should never see them.
Whether your user, server, guest and DMZ networks are really separated, or whether one compromised laptop could reach everything.
Exceptions with no owner, no expiry and no recorded reason, the rules most likely to have outlived their purpose.
Administrative access, authentication, firmware currency, logging and configuration backup, assessed against CIS Benchmarks and vendor hardening guidance.
We review all the mainstream platforms, including Fortinet FortiGate, Palo Alto Networks, Cisco, Sophos, WatchGuard, SonicWall, Check Point and pfSense, plus cloud security groups in Microsoft Azure and Amazon Web Services.
Your review is carried out by a tester holding The Cyber Scheme's Team Leader qualification for infrastructure testing, which is recognised by the NCSC against UK government testing standards. Our lead tester is also a UK Cyber Security Council registered Principal (PriCSP) for Security Testing.
Device configuration is assessed against CIS Benchmarks and the vendor's own hardening guidance, and every rule is read in the context of how your network is meant to work. Automated tooling helps with breadth; the judgement about what actually matters to your business comes from the person doing the review.
A short enquiry, answered by a tester rather than a sales team.
15 to 30 minutes to confirm the firewalls, rule counts and cloud security groups in scope.
Clear scope, clear price, clear dates, typically within 48 hours.
We tell you exactly how to export the configuration securely, then review it and report back.
Once the changes are made, we check the updated configuration at no extra cost.
Cyber Essentials expects every inbound firewall rule to be approved, documented and removed when it is no longer needed. A rules review gives you that evidence, and fixes the gaps before your assessment.
It also pairs naturally with an external infrastructure penetration test: the test shows what an attacker can reach, and the review shows which rules opened the door.
Cyber Essentials certificationIt is a line-by-line review of your firewall rule base and device configuration. We look at what every rule actually allows, whether it is still needed, and whether the device itself is configured securely, then give you a prioritised list of specific changes to make.
No. We work from a configuration export that you or your IT provider sends us securely, so there is no remote access to set up, no change to your network and no risk of downtime. We will tell you exactly how to produce the export for your platform.
All the mainstream platforms, including Fortinet FortiGate, Palo Alto Networks, Cisco, Sophos, WatchGuard, SonicWall, Check Point and pfSense, as well as cloud security groups in Microsoft Azure and Amazon Web Services. If you run something else, ask and we will confirm on the scoping call.
An experienced, senior tester carries out your review from scoping to report. Our lead tester holds The Cyber Scheme's Team Leader qualification for infrastructure testing, which is recognised by the NCSC against UK government testing standards, and is a UK Cyber Security Council registered Principal (PriCSP) for Security Testing. Device configuration is assessed against CIS Benchmarks and the vendor's own hardening guidance.
An external penetration test looks at your perimeter from the outside and shows what an attacker can reach today. A firewall rules review looks at the configuration from the inside and shows why: the specific rules that open those paths, the ones that are no longer needed, and how to tighten them. The two work well together, and many clients pair a rules review with an external or internal test.
Yes. Firewalls are one of the five Cyber Essentials technical controls, and the scheme expects inbound rules to be approved, documented and removed when no longer needed. A rules review gives you exactly that evidence and fixes the gaps before an assessment.
A clear report with an executive summary and each finding graded by severity, alongside the specific rule or setting to change and why. We talk it through with you on a short call, and once you have made the changes we re-review the updated configuration at no extra cost.
It depends on how many firewalls and rules are in scope, so there is no fixed public price. Tell us roughly what you run on a short scoping call and we will come back with a fixed-price quote, typically within 48 hours.
Tell us roughly which firewalls you run and how many rules they carry. We'll recommend a sensible scope and come back with a no-obligation, fixed-price quotation.
A real tester, not a sales team, so the first reply is already useful.
15 to 30 minutes to understand your firewalls and what you need to prove.
Clear scope, clear price, clear dates, typically within 48 hours.
Not sure whether you need a rules review, a penetration test or both? Tell us what you're trying to achieve and we'll help you scope it.