Managed Firewall: The Security Device Someone Has to Run

A managed firewall is a business firewall that an IT provider configures, monitors and keeps patched on your behalf, rather than a device you buy once and forget. The service covers the rule set, the firmware updates, the log monitoring and the change requests that arrive as the business grows.

Managed firewall: flat vector of an internet connection passing through a maintained gateway into a business network.

Most firewalls in small New Zealand businesses were set up properly once. Someone competent came in, worked through the rules with the owner, tested it, and left a tidy configuration behind.

That was four years and two staff changes ago. Since then the business has added a cloud accounting package, three people working from home, a booking system that needed a port opened, and a supplier who asked for remote access to a machine in the back office.

Nobody has looked at the rule set since. The firmware is on whatever version shipped with the box, and the device still blinks, so nobody has thought about it.

Blinking lights are the least reliable security indicator in the building, and they are the one most owners rely on.

A managed firewall closes that gap. It puts the rules, the updates and the log monitoring in someone’s job description, so the protection you paid for four years ago is still the protection you have today.

This is the most common security gap we find in South Island businesses, and it is seldom carelessness. It follows from a device with no owner meeting a business that keeps changing.

What Is a Managed Firewall?

It is a firewall that an IT provider owns as an ongoing service. They design the rule set, apply the vendor’s security updates, watch what the device reports, and make the changes you ask for.

The hardware can still be yours. What you are buying is the work that surrounds it, which is the part that decays without an owner.

The distinction matters commercially, because the two are quoted very differently. A firewall on its own is a capital purchase with a warranty. A managed service is a monthly line item with a person attached, and that person is the part doing the work.

Some providers deliver the same thing from the cloud and call it firewall as a service, or FWaaS. The filtering happens in the provider’s network and there is no appliance in your comms cabinet, which suits businesses with staff spread across many locations.

What is the difference between a firewall and a managed firewall?

A firewall is the device. Managed firewall describes who keeps it correct after the installer drives away.

Every firewall ships with a default configuration that is broadly sensible and specific to nobody. Turning that into protection means writing rules that match how your business actually works, then revisiting them when the business changes. Unmanaged, the rule set becomes a record of every temporary exception nobody removed.

Which businesses need one?

Any business where nobody could tell you, today, what rules are on the firewall and when its firmware was last updated. That covers organisations under about fifty staff without a dedicated IT person.

The other clear case is a business with anything reaching in from outside: staff working remotely, a supplier with access to a server, a booking or payment system exposed to the internet. Each one is a hole opened deliberately that needs reviewing.

Trades and professional services firms are the ones caught out most often. The firewall protects a server holding client records, and its configuration has been inherited three times without documentation.

Multi-site businesses are the other clear case. Each branch has its own device and its own rule set, and keeping three or four of them consistent by hand is where the differences creep in. The site that gets forgotten is the smallest one, because it has the fewest people to notice anything wrong.

What Does a Firewall Do at the Edge of Your Network?

It sits between your internet connection and everything inside, inspecting traffic in both directions and allowing only what the rules permit. Everything else is dropped, and on a well-configured device it is also recorded.

Two directions matter equally. Inbound filtering stops the internet reaching your systems uninvited. Outbound filtering stops a compromised machine inside your office from calling out to an attacker’s server, which is how most infections escalate.

Firewall traffic flow: inbound and outbound traffic filtered into separate staff, server and guest network zones.

What does a next-generation firewall add?

A next-generation firewall inspects what is inside the traffic, down to the application it belongs to. It can tell that a connection is a file transfer, a video call or a known malicious download, and apply a different rule to each.

In practice that means blocking known bad destinations, filtering web categories, and spotting an intrusion attempt as it happens. Older devices could only judge traffic by address and port, which attackers learned to work around a long time ago.

Vendors label these devices next-generation firewalls, usually shortened to NGFW, and sell the wider bundle of filtering and inspection features as unified threat management, or UTM. The labels matter when comparing quotes, because the same capability appears under both.

Segmentation is the other capability worth having. Splitting the network so that the till, the server and the visitor connection sit in separate zones limits how far anything can travel.

Vendors call each of those zones a VLAN. That is exactly the mechanism behind a properly built guest WiFi network.

Where does the firewall stop and other controls begin?

The firewall guards the boundary. It has no visibility of a laptop once that laptop leaves the office, and no view of what happens inside an email a staff member opens.

Those belong to other layers, and the wider discipline of network security covers how they fit together. A firewall is a necessary control and never a complete one, which is why anyone selling it as total protection is overselling.

The zero trust model goes further again. It treats every request as untrusted wherever it arrives from, which matters once staff and systems sit outside any boundary you own. A firewall still has a job in that world; it stops being the whole answer.

Why Do Firewalls Stop Protecting Businesses?

Because the two things that keep a firewall effective, an accurate rule set and current firmware, both decay without announcing it, and neither produces a symptom until something goes wrong.

A firewall that has stopped protecting you looks identical to one that is working. There is no error light for a stale rule, and no alert when the firmware falls three versions behind the vendor’s current release.

What happens when nobody owns the rule set?

It fills up with exceptions. Every rule was added for a real reason at the time, and almost none of them are ever removed.

A port opened for a supplier who stopped working with you in 2023. A remote access rule for a laptop that was replaced. A temporary allowance for a printer that became permanent because nobody remembered it was temporary.

Each one is a door left standing open long after the reason for it walked away.

Rule sets need reviewing on a schedule, and the review needs someone with the authority to remove things. That is a governance problem more than a technical one, and it is the one a firewall with no owner never solves.

There is a simple test. Ask for a list of every rule with a reason written beside each one. If more than a handful come back unexplained, nobody is holding the rule set, and the exceptions have become the policy.

How often does firmware get patched?

On unmanaged devices, seldom, and that has become the more serious of the two problems. Firewalls are now a target in their own right.

The NCSC published joint guidance on edge device security with the Australian, Canadian and United Kingdom agencies. It records that Five Eyes agencies have seen an increase in targeted attacks on edge devices, a category that explicitly names firewalls, routers and VPN gateways.

The reason is straightforward. The device is reachable from the internet by design, so compromising it puts an attacker inside the boundary.

Old vulnerabilities stay useful for years. The NCSC’s cyber threat report notes that historical vulnerabilities, some from 2019 or earlier, are still frequently exploited in New Zealand incidents even though fixes are readily available.

The gap is not knowledge. Nobody applied the update, and on a device with no owner there is nobody whose job it was.

What Is Included in a Managed Firewall Service?

Six things, and a quote that omits any of them is not a managed service. Ask for each one in writing before you sign.

  • Initial design and configuration of the rule set around how your business actually operates
  • Firmware and security updates applied on a defined schedule, with urgent patches out of cycle
  • Monitoring of what the firewall reports, by someone who acts on it
  • Rule changes on request, with a stated turnaround time
  • A scheduled review that removes rules no longer needed
  • Plain reporting on what was blocked, what changed and what needs attention

Managed firewall service checklist: rule design, patching, log monitoring, change handling, reviews and reporting.

Monitoring is where services differ most. A device that logs to itself and is never read is not monitored, and plenty of quotes count that as monitoring. Ask who reads the logs, how often, and what happens at 2am when something is flagged.

Where that answer needs to be genuine round-the-clock cover, it belongs with managed detection and response, which is a separate service with its own cover.

How fast should a rule change happen?

Same business day for a routine change, and within an hour for anything blocking work. Slow change handling is what pushes people into bad habits.

A team that waits three days for a firewall rule will eventually find a workaround, and the workaround is worse than the rule they wanted. Turnaround is a security control in its own right.

Get the turnaround written into the agreement. A provider who will not commit to one on paper is telling you something about how the work is resourced.

Does a managed service help with compliance?

It contributes. Compliance takes more than one control. Information privacy principle 5 requires agencies to protect the personal information they hold with security safeguards that are reasonable in the circumstances, and a boundary control that is kept current is part of what reasonable looks like.

The documentation is what turns a control into evidence. An unpatched device running rules nobody can explain is difficult to defend if you are ever asked what safeguards were in place at the time.

What Does a Managed Firewall Cost in New Zealand?

Budget roughly $150 to $600 a month depending on the size of the site and whether the hardware is included, with a one-off setup fee for the design and migration. The device itself runs from about $800 for a small office to several thousand for a multi-site business.

What you pay for What it covers How it is priced
The firewall itself The appliance or virtual instance, sized to your connection and site One-off, or rolled into the monthly fee
Design and setup Rule set design, migration from the old device, testing and cutover One-off project fee
Management and patching Firmware updates, vendor advisories, rule changes on request Per site per month
Monitoring and reporting Reading what the device reports and acting on it, plus regular reporting Per site per month, often bundled
Licensing Subscriptions for web filtering, intrusion prevention and threat feeds Annual, per device

The variable that moves the price most is the number of sites, not the number of staff. A single office with thirty people is simpler to run than three branches with six people each, because every site is another device, another rule set and another connection to keep current.

It is worth pricing the other side of that comparison. A single day offline, with staff idle and customers unable to reach anyone, costs a small business more than a year of the monthly fee.

Hardware refresh matters too. Firewalls reach an end-of-support date after which the vendor stops issuing security updates, and running past it makes the device a liability. A good contract tells you that date a year out, while you can still budget for it.

Is managing it in house cheaper?

Only if someone in house does the work. The honest comparison is the monthly fee against the hours it would take internally, plus the risk of the job never getting done.

A capable person can run a firewall for a single site. The question is whether the same person is available when a rule is needed on a Friday afternoon, whether they see the vendor advisory the week it lands, and who covers it when they are on leave. Most small businesses discover the answer during the one week it matters.

What Happens If the Firewall Fails?

The site loses its internet connection. Every packet in and out of the building passes through one device, so a hardware fault, a bad update or a power event takes everyone offline until it is restored or replaced.

That is worth settling before it happens. Two questions cover it: how quickly can a replacement device be on site, and where is the configuration backed up so it can be restored onto that replacement.

The configuration backup is the part people forget. Couriering a new appliance is straightforward. Rebuilding four years of accumulated rules from memory is not, and a business that has never exported its configuration finds that out on the worst possible day.

Do you need a second internet connection as well?

Only where a few hours offline would cost real money. For a business taking bookings or card payments over the internet, a backup business internet connection with automatic failover is the cheaper half of the resilience conversation.

Most business firewalls can hold two connections and switch between them without anyone noticing. The cost is a second line rental, not a second device, which surprises owners who assumed resilience meant buying everything twice.

Where the device itself can never be the single point of failure, two firewalls can be paired in what vendors call high availability, so the second takes over automatically. It is overkill for most businesses.

How Do You Move to a Managed Firewall?

Five steps, and the first is the one that gets skipped:

  1. Get the current state documented. What device is it, what firmware, what rules exist and why.
  2. Agree what should be different. Most audits find rules to remove before they find rules to add.
  3. Decide whether the existing hardware stays. If it is past end of support, replacing it is cheaper than working around it.
  4. Cut over outside business hours, with the old configuration kept so you can fall back.
  5. Set the review cycle and the reporting rhythm on day one, so the rule set never drifts again.

A single-site changeover is a few hours of work plus a short outage. The documentation step takes longer than the technical one, and it is worth doing properly, because it is the thing nobody has done since the device was installed.

Two things worth doing this week

Find out when your firewall’s firmware was last updated and when the vendor stops supporting the model. Both answers should take your provider one email.

Then ask for a list of every rule allowing something in from the internet, with a reason beside each. Any rule nobody can explain is one to close.
Get Someone Watching the Edge of Your Network
Exodesk has supported South Island businesses since 1989 and works with organisations across Canterbury, Otago and Southland from offices in Christchurch and Dunedin. We design and run managed firewall services: the rule set built around your business, firmware kept current, logs actually read, and changes handled the day you ask. It sits alongside the rest of our cyber security work.

Contact us today to discuss how we can help your business or connect with us on LinkedIn to stay updated with more insights.

Frequently Asked Questions

What is a managed firewall?
Managed firewall describes an arrangement where an IT provider takes ongoing responsibility for a business firewall: designing the policy, applying vendor updates, reading what the device reports and handling change requests. The appliance may still belong to you. What the service buys is the maintenance work that otherwise stops happening once the installer leaves.
How can I tell whether our firewall is being managed?
Ask three questions: when was the firmware last updated, who approved the most recent rule change, and where is the configuration backed up. A managed service answers all three from records within a day. If the answers take a week to find, you have an installation and nobody holding it.
How much does a managed firewall cost in New Zealand?
Expect roughly $150 to $600 per site each month, depending on site size and whether hardware is included, plus a one-off setup fee for design and migration. The appliance runs from about $800 for a small office. The number of sites drives the price far more than the number of staff.
Does a small business really need a firewall?
Yes. Any business with an internet connection is scanned automatically, and attackers do not check your revenue before probing an exposed system. The realistic question is not whether to have a firewall but whether anyone is keeping it configured and patched. An unmaintained device gives the reassurance of protection without much of the protection itself.
How often should firewall firmware be updated?
On a defined schedule, with urgent security patches applied out of cycle when the vendor issues an advisory. The NCSC has reported that vulnerabilities from 2019 and earlier are still being exploited in New Zealand incidents despite fixes being available, which is a patching failure, not a technology one.
What is a next-generation firewall?
A next-generation firewall inspects the content and application behind a connection, going beyond its address and port. That lets it block known malicious destinations, filter web categories and detect intrusion attempts. Most business firewalls sold today are next-generation devices, though the features sit behind separate subscriptions.
Can a firewall stop ransomware?
A firewall reduces the risk and cannot remove it. It can block known malicious destinations and stop an infected machine calling out, which limits how far an attack spreads. It cannot stop a staff member entering credentials on a convincing fake login page, so it belongs alongside endpoint protection, multi-factor authentication and tested backups.
Who should be able to change firewall rules?
One accountable party, with every change logged and a reason recorded. Shared administrator access with no record is how rule sets fill with exceptions nobody can explain.
What happens to our existing firewall if we move to a managed service?
The existing device usually stays, provided the model is still supported by the vendor. A provider should check the end-of-support date first, because running past it means no more security updates. Where the device is past that point, replacing it is cheaper than the workarounds required to keep it safe.
Does a managed firewall help with Privacy Act compliance?
Yes, in part. Information privacy principle 5 requires agencies to protect personal information with security safeguards that are reasonable in the circumstances, and a maintained boundary control is part of what reasonable looks like. It is one contributing control among several.
Do remote and home-based staff sit behind the office firewall?
Not unless traffic is deliberately routed back through it. A laptop at a kitchen table is on a home connection and outside the office boundary entirely. Covering those staff means either routing their traffic through the business firewall or protecting the device itself, and most businesses now do the second.
Does Exodesk provide managed firewalls in Christchurch and Dunedin?
Exodesk works with organisations across Canterbury, Otago and Southland from offices in Christchurch and Dunedin, and has supported New Zealand businesses since 1989. We design the rule set, keep firmware current, monitor what the device reports and handle changes as part of an ongoing managed service.

Start typing and press Enter to search

Cyber attacks: flat vector of eight arrows approaching a business network, most deflected by a layered defence barrier.Employee efficiency: flat vector of a working day broken into fragments by system waits and interruptions. Call Us Now