Introduction

Firewalls play a crucial role in cyber security, acting as the first line of defence against unauthorised access. Whether your organisation is pursuing Cyber Essentials, Cyber Essentials Plus, or just looking to be secure, a suitably configured firewalls is a fundamental requirement. In this article, we explain why firewalls are so important, make consideration and provide key notes, we also present an example scenario to help with the explanation of the Cyber Essentials requirements.

 

Why Firewalls Are Important

A firewall is a security barrier that monitors and controls incoming and outgoing network traffic based on predefined rules. It helps prevent cyber threats, unauthorised access, and data breaches. Without a firewall, your network and/or devices are exposed to various cyber risks, including malware infections, hacking attempts, and unauthorised access.

Firewalls are especially important for:

  • Protecting sensitive business data
  • Preventing unauthorised access from the internet
  • Blocking malicious traffic 
  • Enhancing regulatory, compliance and security posture

 

What Firewalls Cover in Cyber Essentials

To meet Cyber Essentials certification requirements, organisations must ensure:

  • Default passwords are changed to secure access
  • Internet access to administrative interfaces are prevented unless there’s a documented business need with suitable protection (such as multi-factor authentication)
  • Only necessary ports are open, again with a documented business need
  • All other inbound connections are blocked, including unauthenticated connections  
  • Unnecessary firewall rules are removed or disabled quickly, to reduce exposure 

 

Considerations and Key Notes

When reviewing firewalls for your organisation, please consider:

  • The network boundaries – office, cloud, and/or work at home environment
  • The type of firewalls in use – hardware and/or software firewalls
  • Who manages the firewalls – your organisation or other parties 
  • Whether there’s a business need to access internal services 

 

Key Notes

  • Home broadband ISP devices are out of scope for Cyber Essentials 
  • Best practice cyber security requires two types of firewall are used for protection. One at the entrance or boundary to the network and another on each computer
  • In-built (vendor provided) software firewalls are suitable for Cyber Essentials – no need to purchase a software firewall unless there’s a business need (Microsoft Defender, Mac OS firewall and default Linux firewalls are all acceptable for Cyber Essentials)

 

Example Scenario

Organisation ABC has an office environment using a firewall provided by the organisation

  • For Organisation ABC, a hardware firewall is protecting the office network (boundary)
  • Ensure technical controls are in place for the hardware firewall – change any default password, prevent administrative access from the internet / ensure inbound ports are blocked (unless there’s a documented business need and suitable controls are in place)
  • Document a way to change the password – use this in the event that the password may be compromised
  • For best practice ensure software firewalls are also in use for each computer

 

Tips and Recommendations

  1. Make it clear that you have considered each of your environments when completing the Cyber Essentials question set
  2. Make reference to hardware and software firewalls (assuming software firewalls are being relied upon in some way) on the Cyber Essentials question set
  3. If a third party is responsible for your firewall, ensure that third party manages password control and detail how you confirm the requirements are being met in the question set
  4. Always change any default password and then change again if a compromise is suspected, or if someone leaves the organisation with knowledge of that password
  5. Really consider whether administration is required via the internet – if it is ensure this is documented as a business need and ensure technical controls are in place such as multi-factor authentication with a minimum of 8 character passwords, or a minimum of 12 characters if multi-factor authentication is not possible to setup
  6. If inbound rules are setup to allow access to internal services, ensure this is documented as a business need, that firewall rules are reviewed regularly and disabled when not in use / not required

For more detailed guidance, visit the IASME knowledge hub for Cyber Essentials and review the ‘About Firewalls’ section.

 

How We Help

At RB Consultancy Ltd, we support organisations in implementing firewall security that meets Cyber Essentials and Cyber Essentials Plus requirements:

  • Explain the difference between hardware and software firewalls 
  • Help determine how they should be relied upon for your environment 
  • Explain why the Cyber Essentials questions are being asked and how they intend to protect organisations in different ways
  • Ensure the firewalls to align with Cyber Essentials guidelines

 

Conclusion

Firewalls are a critical component of cyber security and Cyber Essentials certification, helping to protect your business from cyber threats. Misconfigurations, outdated rules, and poor administrative practices can leave your organisation vulnerable. By implementing best practices and ensuring compliance with Cyber Essentials technical controls, organisations can significantly reduce their cyber risk. If you need assistance with firewall configuration, or Cyber Essentials / Cyber Essentials Plus certification, please contact us for support.

 

Written by Remo Belisari, Managing Director of RB Consultancy Ltd, an experienced cyber security professional cyber advisor. Remo holds certifications relating to CISSP, ISSAP, ISO 27001, Cyber Essentials, IASME Cyber Assurance, and has many years experience in IT and cyber security. Remo has a history of supporting organisations from all over the world – including a Fortune 500 in USA and over 100 organisations across the UK. The views expressed in this blog are those of the author and do not necessarily reflect the views of RB Consultancy Ltd, its clients, partners, or affiliated organisations. The content is intended for general information only and should not be taken as legal advice.

 

Cyber Essentials: Firewalls

Other articles you might find useful.

Cyber Security Consultancy: Incident Response

Cyber Security Consultancy: Incident Response

Incident response planning is the difference between a contained breach and a business-ending disaster. Using the 2014 Sony Pictures attack as a case study, we explain what incident response is, why it matters, and how to strengthen cyber resilience.

Read More »
Benefits of Cyber Essentials Plus

Benefits of Cyber Essentials Plus

Cyber Essentials Plus certification goes beyond basic compliance by providing a technical security audit that actively tests your defences against real-world threats. Through hands-on vulnerability

Read More »
Cyber Security Consultancy: Change Management

Cyber Security Consultancy: Change Management

Cyber Security Consultancy: Change Management A single change can bring multiple organisations to a standstill – the July 2024 CrowdStrike incident proved this, causing widespread outages across airlines, hospitals, and banks without any threat actors involved. Effective IT change management and business continuity planning require thorough testing, risk assessment, and rollback procedures before changes go […]

Read More »
Cyber Security Consultancy: Physical and Environmental Protection

Cyber Security Consultancy: Physical and Environmental Protection

Cyber Security Consultancy: Physical and Environmental Protection Cyber resilience goes beyond firewalls and passwords, physical security controls and environmental risk management are equally critical to protecting your organisation. Storm Dennis showed how flooding can destroy server rooms, backups, and operations in hours, highlighting why business continuity planning must account for real-world threats like fire, flood, […]

Read More »
Cyber Security Risk Management: Supply Chain Security & Building Resilience

Cyber Security Risk Management: Supply Chain Security & Building Resilience

Cyber Security Risk Management: Protecting Against Supply Chain Security Risks Effective cyber security risk management is not about eliminating every threat – it’s about understanding what could go wrong and putting appropriate measures in place to protect what matters most. The 2020 SolarWinds attack exposed critical supply chain security risks, with thousands of organisations compromised […]

Read More »
The Top 10 Benefits of Cyber Essentials

The Top 10 Benefits of Cyber Essentials

  Introduction Cyber Essentials is a UK government-backed annual certification scheme that helps organisations protect against common cyber threats. It provides a clear framework for securing devices, networks, and data. By implementing five key technical controls – relating to firewalls, secure configuration, security updates, access control, and malware protection – organisations can significantly reduce cyber […]

Read More »
Get started today

Ready to get certified and
reduce your cyber risk?

Book a free 30-minute discovery call with Remo. No sales pitch, no pressure — just a straightforward conversation about what you need and whether we are the right fit to help.

About RB Consultancy Ltd

Remo Belisari

Founder & Managing Director, RB Consultancy Ltd

Remo Belisari is a Chartered Cyber Security Professional with over a decade of experience advising organisations from start-ups to multinationals across the UK, Europe, Asia and the USA.

Through RB Consultancy Ltd he delivers high-quality, cost-effective and practical cyber security services that support compliance, strengthen resilience and enable business growth.

Remo holds the most respected certifications in the field and is personally involved in every client engagement, ensuring clear and valuable outcomes.

Personal Qualifications

Company Accreditations

Remo Belisari, founder of RB Consultancy
NCSC Assured Cyber Advisor (Cyber Essentials) Cyber Essentials Assessor Cyber Essentials Plus Assessor IASME Cyber Assurance Assessor Vulnerability Assessment Plus (VA+) Certified Defence Cyber Certification - Level 0 Assessor Defence Cyber Certification - Level 1 Assessor
RB Consultancy shield logo blue

RB Consultancy Ltd

Pioneer House, Pioneer Business Park,
North Road, Ellesmere Port, Cheshire,
CH65 1AD

NCSC Assured Service Provider
IASME Certification Body
Chartered (ChCSP) · CISSP · ISSAP