Most UK businesses set up their firewall when they first went online — and then never touched it again. The rules that made sense three years ago are quietly letting in threats that didn’t exist back then. A firewall audit doesn’t need to take a full day. Here’s a structured 30-minute check you can run right now.
Why Your Firewall Rules Go Stale
Firewalls don’t degrade — the world around them does. New services get added, old ones get forgotten, staff leave and their remote access rules stay in place, and software vendors publish new ports that bypass the rules you set up for the old version. The result is a ruleset that looks clean on paper but has gaps you’d be horrified to know about.
The National Cyber Security Centre (NCSC) recommends reviewing firewall rules at least annually as part of Cyber Essentials compliance. For most SMBs, the honest answer is that it hasn’t happened since the thing was installed.
The 30-Minute Audit Framework
Minutes 1-5: Log In and Get the Overview
Pull up your firewall admin panel. You’re not changing anything yet — just looking. How many inbound rules are there? When were they last modified? If you’re seeing rules with comments like “temp – delete after Friday” that are two years old, that’s your first finding. Screenshot the full ruleset before you touch anything.
Minutes 6-12: Attack the Inbound Rules
Go through every inbound allow rule and ask one question: does this still need to exist? Common culprits:
- RDP open to the internet (port 3389). This is the single most exploited entry point for ransomware in UK businesses. If you’re allowing RDP directly, shut it now and use a VPN instead.
- Old VPN or remote access rules for ex-staff. Someone left 18 months ago and their IP-specific rule is still live? Delete it.
- Rules allowing “any” source. If a rule says source: ANY and it’s not for web traffic (80/443), it needs justification or removal.
- Unused application ports. Did you trial a piece of software, open a port for it, and then never buy it? Those test ports are open doors.
Minutes 13-18: Check Your Outbound Rules
Most businesses have almost no outbound filtering. That’s fine for general web browsing, but it means malware installed on a machine can phone home freely. Look for:
- Any outbound block rules — are they still relevant?
- Whether you’re blocking known-bad categories (botnet C2 traffic, high-risk geolocations) at the DNS or firewall layer.
- Whether your business-critical systems could exfiltrate data without triggering any alert.
Minutes 19-24: Cross-Reference Against Active Users and Services
Pull your current list of staff, VPN users, and active services. Compare it against the firewall rules. For each rule, you should be able to name: who needs it, what service it’s for, and when it was last reviewed. If you can’t answer all three, mark it for follow-up.
Minutes 25-30: Document What You Found and Set a Review Date
You won’t fix everything in 30 minutes — and you shouldn’t try. Rushed firewall changes without testing can take services offline. Instead, create a simple action list:
- Rules to delete immediately (RDP open, ex-staff entries, obviously dead rules)
- Rules to investigate further before touching
- Rules that look fine but need a comment added so you know why they’re there
Set your next review date before you close the tab. Three months is reasonable for a growing business; six months is the absolute maximum.
Red Flags That Need Immediate Action
If your audit turns up any of the following, act today rather than adding it to the list:
- RDP or SMB (port 445) open to the public internet
- Default admin credentials on the firewall itself
- Firmware more than 12 months out of date
- No logging enabled (you can’t investigate what you can’t see)
- No alert on failed login attempts to the firewall admin
When 30 Minutes Isn’t Enough
A self-audit is a great starting point but it has limits. If you’re running a multi-site business, have regulatory obligations (Cyber Essentials Plus, ISO 27001, FCA requirements), or haven’t touched your firewall configuration in more than two years, you need a proper external audit rather than a self-review.
An external audit will test your rules from the outside — probing for what’s actually reachable rather than what the ruleset says should be blocked. It’s a different perspective and it catches things that internal reviews miss every time.
Firewall Audit as a Habit, Not a Project
The businesses that get this right treat firewall review the same way they treat fire alarm testing: a short, regular check that takes little time but matters enormously. Build it into your IT calendar now, before something forces you to.
If you’d like a professional firewall review or want to discuss whether your current setup is fit for purpose, get in touch with the Just Firewalls team. We work with UK businesses of all sizes to make sure what’s protecting them is actually doing the job.