Firewall Rules Review

Your firewall, reviewed rule by rule.

Years of quick fixes, temporary exceptions and forgotten rules leave most firewalls allowing far more than anyone intended. We review your rule base and configuration line by line and tell you, in plain English, exactly what to tighten.

Cyber Scheme Team Leader qualified No live access, no downtime Free re-review once fixed
Rule drift

Firewalls don't fail all at once. They drift.

A firewall is only as strong as its rules, and rules pile up. A port opened for a supplier three years ago, an "any" rule added during an outage, objects pointing at servers that no longer exist.

None of it looks dangerous on its own, and nothing alerts you to it. But together it widens the paths into your network and between its parts, often in ways nobody on the team realises. A firewall rules review finds that drift, explains what each problem allows, and gives you a clean, prioritised list of changes.

It is a configuration review, carried out from an export of your settings, so there is nothing to install, no access to arrange and no risk to your live network.

At a glance

What the review does

  • Checks every rule, not a sample
  • Finds risky, redundant and unused rules
  • Tests segmentation against your intended design
  • Benchmarks device hardening against CIS and vendor guidance
  • Gives you the exact change to make for each finding
Scope

What we review

Exposure

Overly permissive rules

Any-to-any rules, broad address ranges and wide-open service definitions that allow far more traffic than the business actually needs.

Housekeeping

Shadowed, redundant and unused rules

Rules that never match, duplicate others or point at retired systems. They add complexity, hide mistakes and make every future change riskier.

Management

Exposed admin and high-risk services

Management interfaces, remote desktop and other high-risk services reachable from the internet or from zones that should never see them.

Segmentation

Traffic between zones

Whether your user, server, guest and DMZ networks are really separated, or whether one compromised laptop could reach everything.

Governance

Temporary and undocumented rules

Exceptions with no owner, no expiry and no recorded reason, the rules most likely to have outlived their purpose.

Hardening

Device configuration

Administrative access, authentication, firmware currency, logging and configuration backup, assessed against CIS Benchmarks and vendor hardening guidance.

We review all the mainstream platforms, including Fortinet FortiGate, Palo Alto Networks, Cisco, Sophos, WatchGuard, SonicWall, Check Point and pfSense, plus cloud security groups in Microsoft Azure and Amazon Web Services.

Delivered to a recognised standard

Reviewed by a qualified infrastructure tester, not a script

Your review is carried out by a tester holding The Cyber Scheme's Team Leader qualification for infrastructure testing, which is recognised by the NCSC against UK government testing standards. Our lead tester is also a UK Cyber Security Council registered Principal (PriCSP) for Security Testing.

Device configuration is assessed against CIS Benchmarks and the vendor's own hardening guidance, and every rule is read in the context of how your network is meant to work. Automated tooling helps with breadth; the judgement about what actually matters to your business comes from the person doing the review.

Deliverables

A report you can act on, and a re-review to prove it worked

The report

Written for the board and the technical team

  • An executive summary in plain English
  • Each finding graded by severity, with what it allows and why it matters
  • The specific rule or setting to change, ready for your team or IT provider to apply
Afterwards

A walkthrough and a free re-review

  • A short call to talk through the findings and agree priorities
  • A re-review of your updated configuration once the changes are made
  • Included as standard, not sold as an add-on
How it works

Straightforward from first email to re-review

  1. Tell us what you run

    A short enquiry, answered by a tester rather than a sales team.

  2. A quick scoping call

    15 to 30 minutes to confirm the firewalls, rule counts and cloud security groups in scope.

  3. A fixed-price quote

    Clear scope, clear price, clear dates, typically within 48 hours.

  4. Send the export, get the report

    We tell you exactly how to export the configuration securely, then review it and report back.

  5. A free re-review

    Once the changes are made, we check the updated configuration at no extra cost.

Working towards Cyber Essentials?

Firewalls are the first of the five controls.

Cyber Essentials expects every inbound firewall rule to be approved, documented and removed when it is no longer needed. A rules review gives you that evidence, and fixes the gaps before your assessment.

It also pairs naturally with an external infrastructure penetration test: the test shows what an attacker can reach, and the review shows which rules opened the door.

Cyber Essentials certification
Where it fits

A rules review supports

  • Cyber Essentials and Cyber Essentials Plus readiness
  • ISO 27001 network security controls
  • Supplier and insurer security questionnaires
  • Clean-up after a firewall migration or merger
Common questions

Firewall rules reviews, answered.

What is a firewall rules review?

It is a line-by-line review of your firewall rule base and device configuration. We look at what every rule actually allows, whether it is still needed, and whether the device itself is configured securely, then give you a prioritised list of specific changes to make.

Do you need access to our firewalls?

No. We work from a configuration export that you or your IT provider sends us securely, so there is no remote access to set up, no change to your network and no risk of downtime. We will tell you exactly how to produce the export for your platform.

Which firewalls can you review?

All the mainstream platforms, including Fortinet FortiGate, Palo Alto Networks, Cisco, Sophos, WatchGuard, SonicWall, Check Point and pfSense, as well as cloud security groups in Microsoft Azure and Amazon Web Services. If you run something else, ask and we will confirm on the scoping call.

Who carries out the review?

An experienced, senior tester carries out your review from scoping to report. Our lead tester holds The Cyber Scheme's Team Leader qualification for infrastructure testing, which is recognised by the NCSC against UK government testing standards, and is a UK Cyber Security Council registered Principal (PriCSP) for Security Testing. Device configuration is assessed against CIS Benchmarks and the vendor's own hardening guidance.

How is this different from a penetration test?

An external penetration test looks at your perimeter from the outside and shows what an attacker can reach today. A firewall rules review looks at the configuration from the inside and shows why: the specific rules that open those paths, the ones that are no longer needed, and how to tighten them. The two work well together, and many clients pair a rules review with an external or internal test.

Does it help with Cyber Essentials?

Yes. Firewalls are one of the five Cyber Essentials technical controls, and the scheme expects inbound rules to be approved, documented and removed when no longer needed. A rules review gives you exactly that evidence and fixes the gaps before an assessment.

What do we get at the end?

A clear report with an executive summary and each finding graded by severity, alongside the specific rule or setting to change and why. We talk it through with you on a short call, and once you have made the changes we re-review the updated configuration at no extra cost.

How much does a firewall rules review cost?

It depends on how many firewalls and rules are in scope, so there is no fixed public price. Tell us roughly what you run on a short scoping call and we will come back with a fixed-price quote, typically within 48 hours.

Get a quote

Find out what your firewall review would cost

Tell us roughly which firewalls you run and how many rules they carry. We'll recommend a sensible scope and come back with a no-obligation, fixed-price quotation.

  1. We read your enquiry

    A real tester, not a sales team, so the first reply is already useful.

  2. A short scoping call

    15 to 30 minutes to understand your firewalls and what you need to prove.

  3. A fixed-price quote

    Clear scope, clear price, clear dates, typically within 48 hours.

Not sure whether you need a rules review, a penetration test or both? Tell us what you're trying to achieve and we'll help you scope it.