Search Projects, Service or Blog.

We are a small business from the Wheatbelt, and we strive to provide very best IT services in the area. With 20+ years of experience, we keep the customer our priority.

Search Now!
Contact Info
Location 23 Johnston St, Dalwallinu WA 6609
Contact Info
Location 23 Johnston St, Dalwallinu WA 6609

Your Firewall is Only as Good as its Configuration

Your Firewall is Only as Good as its Configuration

Images
Authored by
WCS Staff
Date Released
4 September, 2026
Comments
No Comments

Why “we have a firewall” isn’t the same as “we’re protected”…

Ask most business owners what’s protecting their network and they’ll point to the firewall. They’re not wrong—but a firewall is only as good as the way it’s configured and maintained. Even the best appliance won’t protect you if nobody is reviewing the rules, keeping firmware up to date or removing access that’s no longer needed.

Even the best firewall can become a weak point if rules aren’t reviewed, firmware isn’t kept current or old access permissions are left in place. The hardware is only part of the solution. How it’s configured, monitored and maintained is what determines how well it protects your business.

Firewalls aren’t install-once devices. Every network changes over time, and firewall rules need to change with it. As your business changes, your firewall should too. New staff, new software, cloud services and remote access all affect how it should be configured. A firewall configured correctly on day one can become dangerously exposed eighteen months later if nobody has been actively managing it.

One of the most common things we see when taking over support for a new customer is years of old firewall rules that nobody remembers adding. It’s rare that these rules are malicious. Most were created for a project, a contractor or a temporary workaround, then quietly left in place.

What Firewall Misconfiguration Can Lead To

It’s easy to treat “misconfigured firewall” as an abstract IT problem. It isn’t. Here’s what it’s actually looked like in the real world:

Capital One (2019). One of the most well-known breaches of the last decade wasn’t caused by an exotic hacking technique. Capital One disclosed that an attacker exploited a configuration vulnerability in its cloud infrastructure. The incident affected approximately 100 million people in the United States and six million in Canada. It demonstrates why firewall configuration, access permissions and continuous monitoring must work together rather than being treated as separate controls.

Marquis, a financial technology provider (early 2026). In a recent, published ongoing article, investigators are examining if this ransomware and data breach was as a result of exposed firewall configuration files and backup data tied to an unmonitored legacy firewall platform. Investigators found the attackers didn’t need a clever exploit at all — they used what was already sitting there: accessible configuration data and a perimeter device that had quietly stopped being actively watched. The root cause had existed for months before anyone noticed.

Different organisations, different circumstances—but the same underlying problem: security controls that weren’t being actively maintained.

What “Properly Configured” Actually Means

You don’t need to understand packet inspection or VPN protocols to understand the stakes here. Modern firewalls do far more than block unwanted connections. They inspect traffic, identify suspicious behaviour, share intelligence with other security systems and enforce access policies across the network.

A properly configured next-gen firewall should be:
  • Inspect permitted traffic for threats, rather than allowing it simply because it uses a commonly accepted service or port.
  • Use current threat intelligence to identify known threats and suspicious activity that may indicate a newer attack.
  • Share information with compatible security tools so an infected or compromised device can be isolated more quickly.
  • Be reviewed regularly by a technician so temporary rules, outdated access and unused exceptions do not remain in place indefinitely.

Why We Build on Sophos Firewall (XGS Series)

That’s one of the reasons we standardise on Sophos XGS firewalls. We like the platform because it includes tools that make ongoing management and auditing much easier.

A few of the capabilities available through Sophos XGS appliances and SFOS v22 releases:
  • Secure by Design and Health Check — Health Check highlights risky settings and configuration issues so they can be reviewed before they become security problems.
  • Xstream deep packet inspection — When the appropriate inspection policies are configured, Sophos Firewall can analyse permitted traffic—including supported encrypted traffic—to identify hidden threats.
  • Cloud-powered threat intelligence and sandboxing — Unknown files can be safely analysed in Sophos Sandstorm before they’re allowed onto the network.
  • Synchronized Security — When paired with Sophos Endpoint, the firewall can automatically isolate compromised devices in seconds, reducing the opportunity for malware to spread across the network.
  • Post-quantum cryptography readiness — newer releases can identify and control the use of post-quantum encryption algorithms, helping future-proof policy enforcement as this technology starts appearing in real-world traffic.
  • Configuration transparency tools — Sophos has introduced tooling that turns raw firewall configuration into a clear, readable format specifically to make auditing, documentation, and comparison easier — which speaks directly to the “nobody reviewed the rule set” problem behind so many real-world breaches.

These features are only effective if someone is regularly reviewing alerts, refining policies and checking that the firewall still reflects how the business operates. That’s where ongoing management makes the difference.

The Real Lesson

A firewall isn’t a product you buy once. It’s a service you maintain continuously. The businesses that suffer breaches aren’t usually the ones with cheap firewalls — they’re the ones whose good firewalls quietly drifted out of a properly configured state because nobody was actively managing them.

If you can’t remember the last time someone reviewed your firewall rule set—or you’re not sure who has access through it— it’s worth having someone take a fresh look. Firewall reviews are usually straightforward—and they’re a lot less stressful than trying to understand what happened after a breach. Finding a problem during a review is far better than discovering it after an incident.

Wallis Computer Solutions provides managed IT and cybersecurity services, including Sophos XGS firewall deployment and ongoing management, to organisations across Western Australia. Get in touch to have your current firewall configuration reviewed.

 

Regards, 

 

Raymond Thacker
MSP Engineer