Cyber Essentials – Firewalls

Cyber Essentials – Section One – Part 1

Your First Line of Defence

Every day, your organisation’s internet-facing systems receive thousands of unsolicited connection attempts – automated scans, brute-force login tools, and opportunistic malware looking for any open door. Most of these never make the news because a properly configured firewall quietly turns them away before they become a problem. Firewalls are the first of five controls assessed by the UK government-backed Cyber Essentials scheme, and for good reason: without one, everything that follows is built on sand.


What Is a Firewall, and Why Does It Matter?

A firewall is a security control – either a physical device, a software application, or a combination of both -that monitors and filters network traffic. It enforces a set of rules that decide which connections are allowed and which are blocked, based on factors such as the source address, the destination address, and the type of service being requested.

Think of it like a controlled entrance to your office building. You would not leave the front doors unlocked and unattended; you would have a receptionist checking who is arriving and why. A firewall does the same job for your network.

Under Cyber Essentials, the requirement is straightforward: every device that connects to the internet must be protected by a firewall – and that firewall must be configured to block inbound connections that have not been specifically permitted.


What Cyber Essentials Actually Requires

The scheme assesses firewalls across two scenarios:

Boundary firewalls sit at the edge of your network, between your internal systems and the internet. These are typically hardware devices or managed appliances, and they protect the whole network.

Host-based (software) firewalls run on individual devices – laptops, desktops, servers. They are especially important for devices that travel outside the office network, such as remote workers’ laptops connecting from home, hotels, or coffee shops.

The key requirements are:

    • Inbound connections from the internet must be blocked by default, with only specific, business-justified services opened.

    • Unnecessary or unused ports and services must be closed.

    • Default administrator passwords on firewall devices must be changed.

    • Administrative interfaces (the management console) must not be accessible from the internet.

A common failure point is the last one: many small routers and firewall appliances ship with web-based admin panels accessible on port 8080 or 8443 from the internet. This needs to be disabled.


Implementation Advice

Small Business (Up to ~50 employees)

For most small businesses, the “firewall” in scope for Cyber Essentials is your broadband router –  the device your ISP supplied, or one you purchased separately. The good news is that modern routers usually include a basic firewall that blocks unsolicited inbound connections by default. But “usually” is not good enough: you need to verify it.

Practical steps:

    1. Log in to your router’s admin panel. This is usually accessed via a browser at 192.168.0.1 or 192.168.1.1. Check your router’s label for the address and default credentials – and then immediately change those credentials to something strong and unique.
    2. Disable remote management. Look for a setting labelled “Remote Management,” “WAN Access,” or “Remote Administration” and ensure it is turned off. There is almost no reason a small business needs to manage their router from the internet.

       

    3. Review port forwarding rules. If anyone has set up port forwarding (for a CCTV system, a game server, or a legacy application), review each rule. If a forwarded port is not actively needed, remove it. If it is needed, document the business reason.

       

    4. Enable the firewall. This sounds obvious, but some routers ship with the firewall disabled or in a permissive mode. Find the firewall setting and confirm it is enabled.

       

    5. Enable host-based firewalls on all devices. Windows Firewall and macOS’s Application Firewall are both adequate for this purpose and are on by default in recent versions. Confirm they have not been disabled by a user or an application installer.

    6. Consider a guest Wi-Fi network. If visitors or personal devices use your Wi-Fi, put them on a separate network segment so they cannot reach your business systems.

Helpful resources:


Larger Organisation (50+ employees, multiple sites, or complex infrastructure)

At this scale, you are likely dealing with dedicated firewall appliances (Fortinet, Palo Alto, Cisco, Sophos, and similar), multiple network segments, remote workers, cloud infrastructure, and potentially multiple internet connections.

Practical steps:

    1. Establish a formal firewall ruleset and review process. Every rule should have a documented owner, business justification, and expiry review date. Rules accumulate over time – old rules for decommissioned systems, temporary exceptions that became permanent – and a quarterly or annual ruleset review is essential hygiene.
    2. Adopt a default-deny stance. All traffic should be blocked unless explicitly permitted. Do not start from a permissive ruleset and try to block the bad stuff – that approach always loses. Build your ruleset from a clean sheet.

       

    3. Segment your network. Use VLANs (Virtual Local Area Networks) to separate different parts of your organisation -finance systems, guest Wi-Fi, operational technology, servers, and user workstations should ideally be on separate segments. Firewall rules between segments should be as restrictive as possible.

       

    4. Restrict management access. Administrative interfaces for firewalls should only be accessible from a dedicated management network or via a jump host/bastion server. Use multi-factor authentication for firewall admin access.

       

    5. Review internet-facing services. Conduct a regular external scan of your internet-facing IP ranges to identify open ports and services. Tools like Shodan (shodan.io) can show you what the outside world sees. Any open port should have a documented business reason.

       

    6. Address remote workers. Devices that leave the office perimeter must have host-based firewalls enabled and managed centrally – ideally via your MDM (Mobile Device Management) platform. Remote workers connecting to corporate resources should use a VPN.

       

    7. Apply firewall controls to cloud environments. AWS Security Groups, Azure Network Security Groups, and GCP Firewall Rules are your boundary firewalls in the cloud. Apply the same default-deny principles and review them with the same rigour as on-premises kit.

       

    8. Log and monitor. Firewall logs are only valuable if someone is reading them. Ensure logs are forwarded to a SIEM or reviewed regularly. Alert on denied connection spikes, which can indicate scanning activity or a compromised internal host.

Helpful resources:


Common Mistakes to Avoid

    • Assuming the ISP router is “good enough” without checking. It might be – but verify it.

    • Forgetting about home workers’ routers. If a remote employee’s home router is the boundary between your corporate traffic and the internet, it falls in scope for Cyber Essentials.

    • Leaving default passwords in place. The Mirai botnet infected hundreds of thousands of devices by simply trying default credentials. Change them.

    • Treating firewall setup as a one-time task. Networks change. Applications come and go. Rules need reviewing.


What is Next

With your network boundary secured, the next step is ensuring that the devices inside that boundary are properly locked down. That is the subject of our next post: Secure Configuration –  reducing the attack surface of every device you own.


This post is part of our Cyber Essentials Explained series. Read the full series to understand all five controls and what achieving certification means for your organisation

Share This Post

Subscribe To Our Newsletter

Get updates and learn from the best

More To Explore

Do You Want To Boost Your Business?

drop us a line and keep in touch