Why the firewall protecting your business needs more than simply being plugged in.
When business owners hear the word firewall, most understandably assume that having one means the job is done. But think about your business premises.
You might have a strong front door, good locks and an alarm system. But that protection only works if the locks are maintained, the alarm is switched on, and nobody has left accidently left it open. Your firewall is much the same.
It sits between your business and the internet, deciding what should be allowed in and what should be kept out. But simply owning a firewall doesn’t mean it is still protecting you properly.
The problem with “set and forget”
Many business firewalls were installed several years ago. Perhaps your broadband provider supplied the router. Perhaps an IT company installed one when you moved offices. Perhaps a port was opened for an old telephone system, CCTV system, remote desktop service or server.
At the time, everything may have been configured correctly. The problem comes later. Staff change. Systems are replaced. Suppliers disappear. Software reaches end of life. Security vulnerabilities are discovered. Firmware updates are released.
Meanwhile, the firewall quietly carries on running.
- That old rule created three years ago may still be there.
- The login page used to manage the firewall may still be exposed to the internet.
- The firmware may be several versions behind.
Nobody deliberately made the firewall insecure.
Nobody was managing it.
An open port is an open door
You will sometimes hear IT companies talking about “open ports”. For a business owner, the important thing is much simpler. An open or forwarded firewall port can allow internet traffic to reach a service inside your business network. Sometimes that is completely necessary. Your business may have a legitimate service that needs to be reachable from outside.
But every opening should have a reason. An old port forwarding rule for a server that no longer exists is a little like discovering a side door to your building that nobody remembers unlocking. An open port isn’t automatically a security problem.
An unnecessary, undocumented or forgotten open port is.
That is why firewall rules need reviewing rather than simply accumulating over the life of the network.
Cyber Essentials expects more than just having a firewall
This is also an important part of Cyber Essentials, the Government-recommended minimum standard for cyber security. Cyber Essentials requires organisations to block unauthenticated inbound connections by default, document and approve required inbound firewall rules, remove rules that are no longer needed and properly protect firewall administration from the internet.
There is another particularly important requirement: security updates. High-risk and critical security updates and vulnerability fixes for router and firewall firmware must be installed within 14 days of release.
And from April 2026, this has become even more significant. Failing the Cyber Essentials assessment question covering these router and firewall updates now results in an automatic assessment failure.
So the question is no longer simply: “Do we have a firewall?”
It is: “Do we know that our firewall is securely configured and up to date today?”
What does a managed firewall actually mean?
A managed firewall isn’t simply a firewall that somebody installed for you. It means somebody remains responsible for it long after installation.
That includes monitoring its support and firmware status, applying security updates, reviewing internet-facing services, maintaining firewall rules and making changes when your business or the threat landscape changes.
Most importantly, it means there is a clear answer to the question:
“Who’s responsible for keeping this secure?”
The PC Comms difference
Buying a new firewall is not the end of the process. At PC Comms, we believe a business firewall should be treated as a managed security service rather than a piece of equipment that is installed and forgotten.
That means keeping track of the firmware it is running, identifying security updates, reviewing internet-facing services, checking firewall rules, controlling administrative access and understanding when equipment is approaching the end of its supported life. It also means having somebody responsible for acting when something changes. That is where the real difference lies.
For PC Comms, UniFi gives us a consistent platform from which we can deliver that management across our customer base.
Why UniFi
We standardise on UniFi because it gives our team central visibility of the firewalls we manage. We can see firmware and update status, maintain consistent configurations across customer sites and manage changes without relying on somebody remembering to log into an individual router sitting in a cupboard.
That doesn’t make UniFi immune from vulnerabilities. No firewall is. The advantage is that when something needs attention, we have the visibility and management tools to identify it and act quickly.
Do you know what’s protecting your business?
There are a few simple questions every business owner should be able to get an answer to.
- What firewall protects our internet connection?
- Is it still supported by the manufacturer?
- Is its firmware up to date?
- What services are currently exposed to the internet?
- Why are they exposed?
- Who checks for security updates?
- Who reviews the firewall configuration?
- And if a critical vulnerability was announced tomorrow, who would know that our business was affected and do something about it?
If the answer to several of those questions is “I’m not sure”, that doesn’t necessarily mean you need a new firewall. But it does mean somebody should take a look.
Let PC Comms check the front door
PC Comms can review your existing firewall, whether it is DrayTek, UniFi, ISP-supplied equipment or another platform.
We can check what is exposed to the internet, review existing firewall rules, look at firmware and manufacturer support status and identify anything that could affect your security or Cyber Essentials readiness.
Where the existing equipment can be securely maintained, we’ll tell you. Where moving to a centrally managed firewall would give your business better visibility, security and ongoing management, we’ll explain why.
Because the most important question isn’t:
“What firewall have you bought?”
It’s: “Who is looking after it?”
Not sure? Ask PC Comms for a firewall health check.

