Skip to content

Securing Cyber Essentials: Implementing Firewalls and Gateways.

The Boundary Firewalls and Internet Gateways key control is vital for protecting your organisation’s network from unauthorised access and potential cyber threats.

You can think of a firewall as a digital security barrier between your internal network and the wider internet. They act as a doorway that decides whether or not to grant access to your house, or network. This barrier is integral to keeping your organisation safe. Internet gateways are essentially routers, like the router device that you have at home. Routers allow your local devices and networks to access the wider internet, while firewalls define and apply the security rules for traffic moving between them.

The Scope and Goals of the Boundary Firewalls and Internet Gateways Control

This control applies to: All internet-connected devices, including desktop computers, laptops, tablets, routers, and servers.

Its objectives: To ensure that only safe and necessary network services can be accessed over the internet.

For example, you will need to use a firewall software solution that can be applied to your devices and your wider network, which will include your servers. This firewall will act as your digital security barrier by regulating access to your network.

For all devices and firewalls, your organisation will be required to routinely:

  • Change any default administrative password to an alternative that is difficult to guess. Alternatively, you can disable remote login access entirely from any application, excepting the firewall provider’s own web-based management system.
  • Prevent access to the firewall’s admin interface (used to manage firewall configuration) from the internet; for example via a typical home router or a public Wi-Fi device, unless there is a clear and documented business need and the interface is protected by one of the following controls: 1) a second authentication factor, such as a one-time token; or 2) an IP whitelist that limits access to a small range of trusted IP (device) addresses. These two controls help to ensure your Firewall configuration cannot be tampered with by unauthorised actors.
  • Block unauthenticated inbound connections by default
  • Ensure that the firewall’s inbound traffic rules are approved and documented by an authorised individual, with the business need for these rules being included in the documentation
  • Remove or disable permissive firewall rules promptly, whenever they are no longer needed
  • Ensure the use of firewall software on devices that are being used on untrusted networks, such as public Wi-Fi hotspots.

Your Practical Guide to Applying Boundary Firewalls and Internet Gateways

Here’s how to apply these measures in practice. Remember to document these implementations so that you can demonstrate their application in the certification process.

Map Your Network

Begin by mapping out your organisation’s network. You can do this efficiently with a network scanning tool. Identify the devices that are connected to your network, categorise them by their type and role, and record their details such as their device name and IP address. Find out the access points (WiFi devices) that are being used to access your network, and take care to make sure they are secure.

This understanding will help you comprehensively deploy boundary firewalls and internet gateways across your network, providing enhanced security.

Choose the Right Solutions

Select reputable and robust firewall and gateway solutions that are suitable for your organisation’s size and needs. Cloud-based firewalls or firewall hardware are common choices.

Ensure the solutions offer key features such as intrusion detection, content filtering, and virtual private networks (VPNs). VPNs will enable your devices to access your network securely. Devices that try to access your network without a VPN are far less likely to gain access.

Configure Firewalls and Gateways

Set up your chosen solutions by configuring their rules and policies. Only allow necessary inbound and outbound traffic and block unauthorised access attempts. Implement default-deny policies, meaning that everything is blocked unless they are explicitly permitted. For example, you can ensure that unlisted devices outside of your network inventory are denied access by default.

Update Regularly

Keep your firewalls and gateways up-to-date with the latest firmware and security patches. Regularly check for updates from the manufacturers and apply them promptly to protect against emerging threats.

Set Strong Passwords & Authentication Measures

Set strong passwords and authentication mechanisms for accessing the accounts that manage your firewall and gateway configurations. If cyber threats access these, they would be able to change the rules for accessing your network. Limit administrative privileges to as few users as possible to mitigate risks associated with compromised accounts.

strong password

Continuous Monitoring

Implement regular monitoring of your firewall and gateway logs. Many firewall solutions do this automatically and can detect and flag up unauthorised access attempts, as well as unusual activity and behaviour patterns. That said, conducting routine manual inspections of your network activity and documenting them is also recommended.

Secure Remote Access

If your organisation allows remote work, use VPNs to provide secure connections between remote users and the internal network. This ensures that data transmitted over the internet remains encrypted and protected. Even if a router (such as a public WiFi device) is being used to access the internet, the VPN will encrypt the traffic going in and out from your device.

Incident Response Plan

Develop, implement and document an incident response plan that includes procedures for handling security breaches or suspicious activities related to your boundary firewalls and internet gateways.

Get your FREE cyber risk traffic light report

Our Cyber Risk Traffic Light Report is designed to help businesses audit their cyber security posture, enabling them to find risk areas and security gaps and to address them with actionable insights. Get started with your cyber security journey by getting your own Cyber Risk Traffic Light Report  today.

Back To Top