Every internet connection has a firewall of some kind, usually built into the router the provider supplied. The question is whether that is sufficient for your circumstances.
What the router firewall does
Blocks unsolicited inbound connections, and allows outbound ones. That is genuinely useful and it is most of the basic protection.
What it does not do: look at what is inside the traffic, distinguish between a legitimate site and a malicious one, enforce rules between internal network segments, or produce logs anybody could investigate an incident with.
For a business with everything in cloud services, no on-site servers, no remote access and no segmentation, that may be adequate. Many small businesses genuinely are in that position now, and it is worth being honest about it rather than buying equipment for its own sake.
When you need more
You have on-site servers. Anything reachable from outside needs controlled, logged access.
You need remote access. Staff connecting into the office network requires a properly configured endpoint — see VPN and remote access.
You want network segmentation. Rules between internal segments need something capable of enforcing them, as covered in VLANs explained.
You have compliance obligations. Cyber Essentials, industry accreditation or a customer's security questionnaire will ask about boundary controls and logging.
Suppliers need access to systems on your network. This must be controlled and time-limited rather than permanently open.
The features worth paying for
Content and category filtering
Blocks known malicious sites and categories you do not want reached from business machines. The security value is real: much of what goes wrong begins with a click on a link, and a filter that blocks known-bad destinations stops a proportion of it before anything downloads.
Intrusion detection
Inspects traffic for patterns matching known attacks. Useful, and it requires a current subscription to be worth anything, because the value is entirely in the freshness of the signatures.
Application awareness
Recognising what traffic actually is, rather than just which port it uses. Lets you permit or restrict by application, and lets you prioritise — voice traffic ahead of file synchronisation, for example.
Logging you can search
Underrated until an incident. When you need to know what a machine connected to on Tuesday afternoon, either you have the logs or you do not. Retention matters: thirty days is a reasonable minimum.
Geographic blocking
Blunt and frequently effective. If your business has no reason to receive connections from a particular part of the world, blocking them removes a great deal of automated noise.
A firewall with an expired subscription is a rule-based filter with a licence sticker. The features people buy it for are the ones that stop working.
The settings that are usually wrong
Rules that were temporary
The most common finding in any firewall review. A rule opened for a supplier's engineer in 2021, for a project that finished, still permitting access from an address nobody recognises.
Review rules annually. For each, ask who requested it, what it is for, and whether it is still needed. Delete anything without a clear answer.
Management reachable from the internet
The administrative interface should be reachable only from inside the network or through a controlled remote access path. Firewalls with management exposed to the internet are found regularly, and they are targeted specifically.
Default credentials, or shared ones
Individual accounts with multi-factor authentication, not a single password known to three people and a former employee.
Firmware left unpatched
Firewall vulnerabilities are actively exploited, often within days of disclosure, because the device is by definition reachable. Firmware updates matter more here than on almost any other equipment you own.
No outbound restrictions at all
Most businesses permit all outbound traffic. Restricting it — particularly for servers and non-computer devices, which should have very predictable needs — limits what a compromised device can do.
Choosing one
Size it for your internet speed with the security features enabled, because inspection costs throughput and published figures are usually measured with everything switched off.
Understand the subscription cost over three years, not just the hardware price. Check whether your provider will manage it, and whether you can see the configuration and logs yourself.
Ask what happens if it fails. A firewall is a single point through which everything passes. For businesses where an outage is expensive, a spare unit with a saved configuration is cheap insurance.
What a firewall does not do
It does not stop a member of staff entering credentials on a convincing fake login page. It does not stop a compromised supplier email. It does not protect laptops once they leave the building.
Which is why it is one layer among several: patched systems, multi-factor authentication, tested backups and trained staff. The wider picture is in the Cyber Essentials guide.
Our security team specifies, configures and reviews firewalls for UK businesses, including rule reviews on equipment you already have. Start a conversation.








