What you get
What a managed firewall includes
A firewall is not a box you buy once. It is a policy that has to be written, deployed and then kept current.
Business-grade firewall
Sized to your connection and your user count, configured to a written policy rather than shipped on defaults, and kept on current firmware.
Intrusion prevention
Traffic inspected against known attack signatures and dropped at the edge, before it reaches a workstation where it becomes your problem.
Content filtering
Categories you choose blocked for staff, with a report of what was blocked and why — not a silent block nobody can explain.
Secure remote access
A proper VPN for staff working off-site, so remote work never means exposing a desktop directly to the internet.
Network segmentation
Staff, guest, payment terminals and cameras separated, so one compromised device cannot reach everything else in the building.
Logging and monthly review
Logs retained and actually read, then summarised in plain English by the same people who configured the rules.
How it runs
How we secure a small network
Assessment first. We will not quote hardware before we know what is exposed.
Security assessment
We look at what is reachable from outside, what is unpatched, and which rules nobody can explain any more.
Design the policy
We write down what should be able to talk to what, and what should never be able to.
Deploy and cut over
Installed and switched over out of hours where a daytime cut would interrupt trading.
Monitor and review
Logs reviewed monthly, rules revisited as the business changes, firmware kept current.
Symptoms
What leaves a small business exposed
Almost none of these are exotic. They are the ordinary gaps attackers scan for, all day, automatically.
- Remote desktop exposed directly to the internet
- The ISP router doing duty as the only firewall
- Firmware three years out of date
- Guest Wi-Fi on the same network as the tills
- No record of what was blocked, or why
- A staff VPN set up once and never reviewed
- Port forwards nobody can explain any more
- Cameras and door controllers reachable from outside
The difference
ISP router versus a managed firewall
The box your provider supplied is designed to give you internet, not to defend a business.
| ISP-supplied router | Managed firewall | |
|---|---|---|
| Inspection | Basic address translation | Stateful inspection plus IPS |
| Updates | Rarely, if ever | On a schedule |
| Policy | Whatever the defaults were | Written for your business |
| Remote access | Port forwarding | Proper VPN |
| Visibility | None | Monthly plain-English report |
| When something happens | You hear about it from a customer | We see it in the log |
Service area
Where we install and manage firewalls
On-site installation across the Lower Mainland, with monitoring, rule changes and reporting handled remotely from Surrey.
Questions
Network security questions we get asked
Do small businesses in Surrey really get attacked?
Not targeted by name, no — which is exactly why it happens. Automated scanners work through every address on the internet looking for an open port or an unpatched service. Being small does not make you invisible to a machine.
Is the firewall built into my internet router enough?
For a household, usually. For a business it lacks intrusion prevention, meaningful logging, network segmentation and a proper VPN, and its firmware is often years behind.
What is a managed firewall?
A business firewall that somebody is responsible for: rules written to a policy, firmware kept current, logs reviewed, and changes made when your business changes rather than left as they were on install day.
What does intrusion prevention actually do?
It inspects traffic against signatures of known attacks and drops matches at the edge. It is the difference between a threat arriving at a workstation and never reaching your network at all.
Can staff still work from home safely?
Yes, over a VPN, which is the safe way to do it. The unsafe way — forwarding remote desktop straight to a PC — is one of the most common causes of ransomware in small business.
How often should firewall rules be reviewed?
Monthly for the logs and at least annually for the rules themselves, plus any time staff, premises or systems change. Rules accumulate, and old ones quietly become holes.
Next step
Let's see what you're running now.
One visit. We map what you have, tell you what is fine, and put a number against what is not. Nothing owed afterwards.