Cyber Essentials 101: Firewalls February 21, 2025 – Posted in: Cyber Security – Tags: Cyber Essentials, Cyber Essentials 101, Cyber Security, CyberEssentials, cybersecurity, ITServices, ITSupport, SmallBusiness
This is the fourth article in our Cyber Essentials 101 series, if you haven’t yet read the first part covering why you should consider Cyber Essentials and how to answer the initial questions about your organisation you can find it here.
A firewall is the software or a hardware device which provides protection between your network devices and the Internet. Your organisation will have physical, virtual or software firewalls at your internet boundaries. Software firewalls are included within all major operating systems for laptops, desktops and servers and need to be configured to meet compliance. Hardware firewalls are powerful devices, which need to be configured correctly to provide effective security. Please note – home routers not supplied by your organisation are not included in these requirements. You can get more information from IASME on this section here.
The rest of the questionnaire is best completed by your IT team, with support of management. It’s vital that whoever signs off the assessment has a solid understanding of the questions and answers in all sections so they can officially sign off on the accuracy.
A4.1 – Do you have firewalls at the boundaries between your organisation’s internal networks, laptops, desktops, servers and the internet?
Why are they asking you this?
Firewalls are key to protecting your network from external threats. They’re the door that separates the safer, internal network from the chaos of the wider internet.
What’s the detail?
Your firewall may be a separate hardware device, or it could be built into your router.
Example answer:
1x Draytek 2862 Firewall & Router – version 3.9.9.2_BT
A4.1.1 – When your devices are being used away from your workplace, how do you ensure they are protected?
Why are they asking you this?
Having policies in place to make sure that your data is as safe when people are working outside the office as it is when they are working inside the office is vital if you want to allow remote working.
What’s the detail?
This section includes computers used by homeworkers, and any devices used that are not connected to your internal network. Solutions that will be relevant to this question are operating system firewalls, VPN connections to the office and gateway servers for remote connections.
Example answer:
All devices, including those used by remote workers, are required to have a software firewall. Access to company data is only available via MFA protected cloud services (e.g. 365 for email) or via VPN for file access.
A4.2 – Have you changed all the default passwords on your boundary firewall devices?
Why are they asking you this?
When you first receive an internet router or hardware firewall device, it will likely have had a default password on it. These default passwords are widely available on the internet and are often not unique to each device.
Example answer:
You should always change the default passwords so the answer to this question should be yes.
A4.2.1 – Please describe the process for changing your firewall password?
Why are they asking you this?
As above, changing passwords is important and it is vital you have something in place that makes sure nothing slips under the radar.
What’s the detail?
You will need to have a policy in place for how you change these passwords and who can request a password change.
Example answer:
Our policy is that when a new device is sourced the first item in our IT Team’s process is to change the password on the device.
A4.3 – Is your new firewall password configured to meet the ‘Password-based authentication’ requirements?
Why are they asking you this?
Passwords are only as strong as their quality denotes. A weak password is crackable in minutes, you should have policies in place to ensure all passwords meet minimum standards.
What’s the detail?
You can (and should be able to) select multiple options here. These are the basic requirements for a secure password and should apply to any password you use. There is more information available here: https://www.ncsc.gov.uk/files/Cyber-Essentials-Requirements-for-Infrastructure-v3-1-January-2023.pdf.
Example answer:
- Multi-factor authentication, with a minimum password length 8 characters and no maximum length.
- Automatic blocking of common passwords, with a minimum password length 8 characters and no maximum length.
- A password minimum length of 12 characters and no maximum length.
- None of the above, please describe.
A4.4 – Do you change your firewall password when you know or suspect it has been compromised?
Why are they asking you this?
It might seem like an obvious one, but it is important to be able to spot a compromised password and make sure everyone knows who has responsibility for changing it.
What’s the detail?
This should be related to your answer for A4.2.1, but include more detail around how you monitor for potentially malicious activity or signs of a compromised password and the chain of command and protocols for changing the password.
Example answer:
Additional to the policy stating that when a new device is sourced the first item in our IT Team’s process is to change the password on the device we monitor known password exposure lists and changes on the software configuration carefully. If there is any indication that a password has been compromised, it will be changed by our outsourced IT team. Password changes can be requested by our outsourced IT team or by any staff member if they have concerns, but can only be approved by senior technicians in our IT team or our senior staff.
A4.5 – Do you have any services enabled that can be accessed externally through your internet router, hardware firewall or software firewall?
Why are they asking you this?
Ports on your router/firewalls are essentially doors that allow different services to communicate from outside your network to devices inside it, or from inside your network to devices outside it. Open ports are a risk factor. This doesn’t mean you won’t use them – it just means you need to have considered the risks and mitigated them.
What’s the detail?
By default most firewalls block all services so unless your IT team have opened a port the answer is no. Examples of services that may be accessible externally include VPNs, a mail server, a client login area hosted on your internal servers, a VoIP phone system, or a Remote Desktop Gateway.
Example answer:
Yes or no.
A4.5.1 – Do you have a documented business case for all of these services?
Why are they asking you this?
Only answer this if the answer to A4.5 is yes. You need to prove that you have thought about the risks of opening a port and have a good reason to do so.
What’s the detail?
It is important to have a documented reason for why a port needs to be open, these business cases must be signed off at board level and reviewed regularly to make sure that the risks are understood and the requirement is still relevant.
Example answer:
Our phone system is integral to our business and our phone system requires port 5060 to be open. This is documented.
A4.6 – If you do have services enabled on your firewall, do you have a process to ensure they are disabled in a timely manner when they are no longer required?
Why are they asking you this?
Only answer this if the answer to A4.5 is yes. It’s important that reviews aren’t simply done on the install of a service – you need to show that you continue to review whether a service is required and that you close ports if a service is no longer required.
What’s the detail?
A similar answer to the use case review above will be fine here, but additionally add the protocols for stopping using a service. For example:
Example answer:
The board reviews all open ports on a biannual basis and our IT team provide risk assessments taking into account current threats. Should the business case change and the service is no longer required will close the port. Additionally our offboarding protocol for any service includes reviewing and changes to the network or systems that may have been made as part of the setup and can now be reversed – including open ports being closed.
A4.7 – Have you configured your boundary firewalls so that they block all other services from being advertised to the internet?
Why are they asking you this?
This is one of the things you have a firewall for. Its job is to protect things inside the network from things outside the network.
What’s the detail?
By default most firewalls block all services from inside the network from being accessed from the internet, but you need to check your firewall settings.
Example answer:
The answer to this should always be yes.
A4.8 – Are your boundary firewalls configured to allow access to their configuration settings over the internet?
Why are they asking you this?
As default it is possible to access a router from outside of your business with nothing more than your public IP address – something that can be found out from a simple search. There is a login page protecting the internal workings, but there is no point exposing even that to anyone who doesn’t need access.
What’s the detail?
You might need to configure your router or firewall to allow external people, such as an IT support company, to change the settings via the internet. If you haven’t set up your firewalls to be accessible to people outside your organisations or your device configuration settings are only accessible via a VPN connection, then answer no to this question.
Example answer:
Yes or no.
A4.9 – If you answered yes in question A4.8, is there a documented business requirement for this access?
Why are they asking you this?
Only answer this if the answer to A4.8 is yes. As with the ports you need to prove that you have actively considered the risks of opening up your router for access
Example answer:
The answer to this question should always be yes.
We have a documented business requirement for our outsourced IT Company to have access to our routers externally. We have considered the risks and put in place mitigations (please see the answer to 4.10).
A4.10 – If you answered yes in question A4.8, is the access to your firewall settings protected by either multi-factor authentication or by only allowing trusted IP addresses combined with managed authentication to access the settings?
Why are they asking you this?
Only answer this if the answer to A4.8 is yes. Essentially this is asking – are you using the available tools to mitigate the risk of making your router or firewall accessible from outside your office.
What’s the detail?
These are mitigations that protect your router or firewall – locking down access to people coming in from your IT company’s IP address, or putting in place multi-factor authentication will help prevent malicious actors from accessing your router or firewall, where they could open ports for malicious software to attack through.
Example answer:
The answer to this question should always be yes.
Access to my router and firewall is locked down to the IP address of the outsourced IT Company.
A4.11 – Do you have software firewalls enabled on all of your computers, laptops and servers?
Why are they asking you this?
Software firewalls lock down your computer to make sure that only allowed services can reach and influence your device from outside your own system. You should always have one in place on your PC, laptop or server.
Example answer:
The answer to this question should ideally always be yes.
A4.12 – If you answered no to question A4.11, is this because software firewalls are not installed by default as part of the operating system you are using? Please list the operating systems.
Why are they asking you this?
Only answer this if the answer to A4.11 is no. Here you can explain why you aren’t using built-in firewalls if the reason is that they’re not available for that operating system.
What’s the detail?
If you cannot have software firewalls on all devices you’ll need to list the operating systems of those devices. If you can have software firewalls in place you always should. All modern Windows or MacOS operating systems include a software firewall.
Some Linux operating systems do not have a software firewall, though most lock down ports by default.
Example answer:
1x PC running up to date Linux Mint
Next Time…
Next week we will cover the Secure Configurations section of Cyber Essentials.
If you’d like help reviewing what you’d need to do to be compliant, filling in the paperwork, or working with your staff to smooth any required changes, we can help. Give us a call on 01245 265 100 or email .