Most businesses rely on the internet for almost everything: email, Microsoft 365, cloud apps, remote working and online banking. Very few stop to think about what is quietly checking all of that traffic. That job belongs to your firewall.
This guide explains in plain English what a firewall does, the different types you will come across, what Cyber Essentials expects from yours, and the mistakes we see most often when we review Sussex businesses’ networks.
What a firewall actually does
A firewall sits between your network and the internet and decides which traffic is allowed through. Think of it as the security desk at the front of your building: it checks who is coming in, where they are going, and turns away anything that does not match the rules.
A well-run firewall blocks unrequested inbound connections by default and only allows what the business needs.
The key principle is default deny: anything not explicitly allowed is blocked. Traffic your staff start (browsing a website, sending an email) is allowed back in, but unrequested connections from the internet are stopped at the door.
Why every business needs one
The Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses identified a breach or attack in the last 12 months, rising to 65% of medium-sized businesses. Automated tools scan the whole internet around the clock looking for exposed remote desktop services, old VPNs and devices with default passwords. Being a small business does not make you invisible to them.
A properly configured firewall:
- stops most of that automated scanning before it reaches your devices
- keeps remote access services such as RDP off the open internet
- lets you separate guest Wi-Fi, phones and CCTV from the computers that hold business data
- gives you logs, so you can see what happened if something does go wrong
The main types of firewall
Most small businesses need a combination: a business firewall at the office, plus the software firewall switched on and managed on every laptop.
What Cyber Essentials expects
Firewalls are one of the five technical controls in Cyber Essentials. The current requirements (v3.3, the Danzell question set, in force since 27 April 2026) expect you to:
- Change the default admin password on every firewall and router to a strong, unique one, or disable remote administration entirely.
- Protect the admin interface. It must not be reachable from the internet unless it is protected by multi-factor authentication or limited to an allow list of trusted IP addresses.
- Block unauthenticated inbound connections by default.
- Approve and document every inbound rule, including who approved it and the business reason it exists.
- Remove rules you no longer need, promptly.
- Turn on the software firewall on devices used on untrusted networks such as home or public Wi-Fi.
Read more in our guide to the Cyber Essentials 2026 changes.
Common firewall mistakes we see
- Default passwords still set on the router or firewall admin page.
- Old “temporary” rules opened for a supplier years ago and never closed.
- Remote desktop exposed to the internet instead of sitting behind a VPN with MFA.
- Out-of-date firmware. Firewall vendors regularly patch serious vulnerabilities, and unpatched VPN appliances are a common way in for ransomware gangs.
- One flat network, where guest Wi-Fi, smart TVs and CCTV share a network with the finance PC.
- Nobody watching the logs, so warning signs go unnoticed.
Firewalls work best as part of a layered defence
A firewall is one layer, not the whole answer. Most attacks now arrive by email or through stolen passwords, which a firewall cannot stop on its own. Combine it with:
- Web filtering to block known malicious and phishing sites
- Email security (see our guide to stopping spam and filtering attacks)
- Multi-factor authentication on Microsoft 365 and remote access
- Patching and supported software (why unsupported software is a risk)
- Backups that are tested and kept separate from your network
Our small business guide to cyber security covers each of these layers.
A quick firewall health check
- Know what you have: make, model and firmware version of every router and firewall.
- Check the admin login: a unique strong password, with MFA where supported.
- Review the rules: can someone explain why each inbound rule exists?
- Update the firmware and switch on automatic security updates if available.
- Separate your networks: guest, staff and devices such as phones and CCTV.
- Confirm someone is monitoring alerts and logs, and knows what to do.
If you cannot tick all six, it is worth a review. As an NCSC Assured Service Provider (Cyber Advisor for Cyber Essentials) and a Sussex managed IT provider since 1996, we check firewalls against the Cyber Essentials requirements every week.
Frequently asked questions
What does a firewall do for a small business?
It controls which traffic can pass between your network and the internet. It blocks unrequested inbound connections, keeps services such as remote desktop off the open internet, and can separate guest Wi-Fi and other devices from your business computers.
Is the firewall in my broadband router enough?
For a very small office it can be a starting point, but router firewalls are often left on default settings and rarely updated. Most businesses benefit from a managed business firewall with web filtering, VPN and reporting, plus the software firewall turned on on every laptop.
Do I need a firewall for Cyber Essentials?
Yes. Firewalls are one of the five Cyber Essentials technical controls. Under v3.3 (Danzell) you need non-default admin passwords, a protected admin interface, inbound connections blocked by default, and documented approval for every inbound rule.
Does a firewall stop phishing and ransomware?
Not on its own. Web filtering on a firewall can block many known malicious sites, but most attacks start with email or stolen passwords. You also need email security, multi-factor authentication, patching and tested backups.
How often should firewall rules be reviewed?
At least once a year, and whenever a supplier, system or remote access method changes. Remove any rule that is no longer needed, and keep a note of who approved each rule and why.
Do home workers need a firewall?
Yes. Laptops used at home or on public Wi-Fi should have the built-in software firewall switched on and managed centrally, so the protection travels with the device.
Not sure your firewall is doing its job?
We will review your firewall and router settings against the Cyber Essentials requirements and give you a plain-English list of what to fix. No obligation.
Sources
- GOV.UK: Cyber security breaches survey 2025/2026
- NCSC: Cyber Essentials requirements for IT infrastructure
- NCSC: Small Business Guide
Do not just read it. Act on it.
Reading is the easy part. Book a free IT review and we will tell you, in plain English, where your business stands and what to fix first.