The firewall you own is the router your broadband company posted you
Seventy-four per cent of UK businesses told the government last winter that they have firewalls covering the entire network as well as individual devices. That puts firewalls near the top of the survey, alongside malware protection and password policies. It is also an answer to a question about whether a thing exists, which is not the same as a question about whether anyone has looked at it.
In most small offices the firewall came in a box from the broadband company. Someone plugged it in on move-in day and pushed it to the back of the cupboard. It is still working. Nobody in the building could tell you the password, and nobody has any idea what it currently lets through.
What the survey actually counted
The Cyber Security Breaches Survey for 2025/2026, run for DSIT and the Home Office across 2,112 businesses and 1,085 charities, puts network firewalls at 74 per cent of businesses and 45 per cent of charities. Among large businesses it is 93 per cent.
Drop one row down the same table and the picture changes. Separate Wi-Fi networks for staff and visitors: 38 per cent of businesses. That has climbed from 33 per cent the year before, so the direction is right. Large businesses went the other way, from 93 per cent to 85 per cent, which is a genuinely odd little number and nobody has explained it. A VPN for staff connecting remotely sits at 36 per cent.
So roughly three in four businesses own the box, and roughly one in three has done anything with it beyond plugging it in. Awareness of Cyber Essentials, meanwhile, is 17 per cent. Most of the businesses that own a firewall have never read what a firewall is supposed to do.
What Cyber Essentials asks of a firewall
Worth reading even if you never intend to certify, because it is the shortest published description of a properly configured boundary that exists in this country, and it is free.
The current document is Requirements for IT Infrastructure v3.3, dated April 2026. Firewalls is the first of the five controls and it applies to boundary firewalls, desktop computers, laptops, routers, servers and cloud services. The stated aim is one sentence: to make sure that only secure and necessary network services can be accessed from the internet. The requirement is that you protect every device in scope with a correctly configured firewall, or a network device with firewall functionality, which is where your router comes in.
Then five things you have to do to it. Change the default administrative password to something strong and unique, or disable remote administrative access altogether. Keep the administrative interface off the internet unless there is a clear, documented business need, and where there is, put multi-factor authentication in front of it or an allow list limited to a small range of trusted addresses with proper password management behind it. Block unauthenticated inbound connections by default. Get inbound rules approved and documented by an authorised person, with the business need written into the documentation. Remove or disable rules once they are no longer needed.
Notice that only one of those five is about the hardware. The other four are administration, and four out of five is roughly the ratio we find in the field.
The interface nobody logs into
The default administrative password is the one on the sticker. On plenty of consumer routers it is also derived from something printed on that same sticker, which is worth knowing before you decide it counts as unique.
Remote management is the more interesting one. Most routers ship with it off, and if yours is off, the requirement is satisfied without you doing anything. The trouble is that it does not usually get switched on by an attacker. It gets switched on by a person, on a Thursday, so an engineer can look at something without driving over, and then it stays on for four years because switching it back off was nobody's job. The same is true of every port forward ever created.
That is why the last of the five requirements exists, and it is the one people ignore. Rules are easy to add under pressure and nobody ever schedules time to take them away.
There is a law about the box itself
This part is newer than most people realise and almost nobody in a small business has heard of it.
The Product Security and Telecommunications Infrastructure Act 2022, together with regulations made under it in September 2023, has applied since 29 April 2024. It is consumer protection law rather than security regulation, and it puts three duties on the manufacturer of a connectable product sold in the UK.
Passwords first. They have to be unique per product, or set by the user. A unique password cannot be based on an incremental counter, cannot be based on or derived from publicly available information, and cannot be derived from a serial number or similar identifier unless that is done with proper encryption or a keyed hash. It also cannot be otherwise guessable. The days of a whole product line shipping with admin and password are over, at least for anything sold new here.
Second, the manufacturer has to publish a point of contact for reporting security issues, and say when a reporter will get an acknowledgement and status updates. That information must be accessible, in English, free of charge, and available without asking you to hand over your own personal details first.
Third, and this is the useful one, they have to publish the defined support period. The regulations define it as the minimum length of time, expressed as a period with an end date, for which security updates will be provided. It has to be written so a reader without technical knowledge can understand it, and where a manufacturer invites you to buy the product it has to be given equal prominence to the price. There is a sting in the tail as well: the requirement is not met if the support period is shortened after it has been published. A manufacturer can extend it. Quietly pulling it back in is not allowed.
Go and look up your own end date
Turn the router over. There is a label with a model number on it, usually next to the serial and the default Wi-Fi key. Search the manufacturer's own site for that exact model and the phrase security update.
You will get one of three answers. A date in the future, which is the good outcome and worth writing into your asset register next to the device. A date in the past, which means the model still routes packets perfectly well and will never be fixed again. Or nothing findable at all, which usually means the hardware predates the regime and tells you how old it is.
An out-of-support router is the same argument as an out-of-support operating system, and we have made that argument at length. The device does not stop working on the day support ends. It stops getting repaired. Every vulnerability found in it after that date is permanent. The difference with a router is that it sits at the edge of your network by definition, which is the one place you would least like permanent to apply.
Firmware for firewalls and routers is also inside the Cyber Essentials update scope alongside operating systems and applications, and since April 2026 that question is an automatic fail if you get it wrong. We covered what that scope actually includes separately.
Guest Wi-Fi, and the honest limit of the scheme
Here is something the certification will not tell you off for.
Cyber Essentials scopes wireless devices in if they can be reached over the internet, and out if an attacker cannot attack them directly that way. The requirements say plainly that the scheme is not concerned with attacks that can only be launched within the signal range of the wireless device. Wireless access points that are part of an ISP router at a home or remote location are out too.
So a business that gives every visitor the same Wi-Fi password its staff use can pass the assessment on that point. It should not feel good about it. That contractor's laptop, which you have never seen and cannot patch, is now on the same flat network as the accounts machine and the NAS in the corner. A separate visitor network takes twenty minutes on most business-grade kit, and on a fair number of ISP routers it is one toggle in the app.
Certification schemes draw a boundary around what they can fairly assess. That boundary is not a safety rating, and treating it as one is how businesses end up certified and exposed at the same time.
Home workers and the router you did not buy
Since more than a third of businesses now have staff connecting from home, the scope rules matter.
The default is that all home and remote working devices used for your business are in scope. If your organisation gives the home worker a router, that router is then in scope as well. Every other router is out of scope, and the answer for those is to apply the firewall controls on the device itself with a software firewall.
Read that middle sentence twice, because it catches good employers. Buying somebody a decent router so their video calls stop breaking up is a kind thing to do. It also quietly moves a device you cannot see into the estate you are accountable for. If you are going to do it, manage it: know the model, change the credentials, note the support date.
The software firewall side is easier than people expect. The requirements note that most desktop and laptop operating systems now come with one, and advise turning that on rather than buying a third-party product. What they insist on is that a device used on an untrusted network, and public wifi hotspots are the example given, has its own firewall running. If somebody works from a hotel twice a month, that is the control that covers them.
If you run a corporate VPN back to the office, the internet boundary moves to your own firewall, which is tidier. The requirements add a condition worth catching: you have to administer that VPN yourself, so the firewall controls can actually be applied to it.
What we do with this, and what it costs
Firewall and network work is a published part of what we sell rather than something we are inventing for an article. Perimeter and internal controls, secure configuration and network segmentation sit on our cybersecurity page, and firewalls, switches and Wi-Fi coverage planning sit under networks and servers on managed IT support. Managed network devices are a line item at £34 each per month, on top of the per-user plans at £50, £77 and £108 per user per month excluding VAT. Servers are £162 each per month.
If it is the certification you are after rather than the engineering, Managed Cyber Essentials is £99 per client per month and covers the gap assessment, the remediation, the submission and keeping the five controls in place through the year rather than scrambling at renewal.
Two things we will not claim. We do not hold Cyber Essentials or Cyber Essentials Plus ourselves, and we are not an assessor, so everything above is a reading of a published document rather than a ruling. And we do not issue certificates. Only a certification body licensed by IASME does that.
Our free ten-question IT health check says on its own page that ten questions cannot see your firewall rules. That is true, and it is the reason the full check exists. Without an agreement, work like this is £126 an hour, against £86 for clients on a plan, and the first look costs nothing either way.
Five things to check this week
None of this needs a purchase order.
- Log into the router. If nobody in the building can, that is your first finding and it is a bigger one than it looks.
- Change the administrative password if it is still the one on the sticker, and put the new one in your password manager rather than on a note taped to the wall.
- Find remote management and turn it off. If you genuinely need it, write down why, and put multi-factor authentication or an address allow list in front of it.
- Read the port forwarding list out loud. Delete anything nobody present can explain. This is usually the twenty minutes with the highest return in the whole exercise.
- Look up the model's published support end date and write it next to the device in your asset register, beside the ones you already track for the laptops.
If you would rather somebody else read that rule list, we will scan what your business publishes to the internet before we visit and show you the findings either way. Ring 020 3411 1886 or use the contact form.
Frequently asked questions
Is the router my broadband provider gave me a firewall?+
Usually yes, in the sense that matters. It blocks unsolicited inbound traffic by default, which is the single most useful thing a boundary device does, and Cyber Essentials names routers alongside boundary firewalls in the same control. So the question is not whether you have one. It is whether anybody has logged into it since it was plugged in, whether the administrative password is still the one printed on the sticker, and whether the manufacturer is still shipping security updates for that model.
Do we need a separate firewall, or is the ISP router enough?+
For a lot of small offices the router is genuinely enough, and we will say so. It stops being enough when you need things it cannot do: separate networks for staff and visitors that are actually separate, rules you can read and audit, logs that survive longer than a reboot, or a site-to-site connection. Those are the reasons to buy a proper firewall, and they are business reasons rather than fear ones. A device you never configured is not made safer by costing more.
What is a defined support period and where do I find ours?+
It is a term from the Product Security and Telecommunications Infrastructure regime, and the regulations define it as the minimum length of time, expressed as a period with an end date, for which security updates will be provided. Since 29 April 2024 the manufacturer of a consumer connectable product sold in the UK has had to publish it, free, in English, understandable without technical knowledge, and without asking you for personal details first. Find the model number on the label underneath the router, then look for that model on the manufacturer's own site. The regulations also say the period cannot be shortened once it has been published.
Does Cyber Essentials require a separate guest Wi-Fi network?+
Not as such, and this surprises people. The scheme scopes wireless devices out where an attacker cannot reach them directly from the internet, and says in terms that it is not concerned with attacks that can only be launched within the signal range of the device. So handing a visitor the same Wi-Fi password your staff use is not an assessment failure. It is still a bad idea, because that visitor's laptop is now on the network with your server. The scheme boundary and the risk boundary are not the same line. Alpha IT does not hold Cyber Essentials or Cyber Essentials Plus and is not an assessor, so read that as our reading of the published requirements.
Our staff work from home. Whose router is in scope?+
The requirements are unusually direct about this. Home and remote working devices used for your business are in scope by default. If your organisation gives the home worker a router, that router is in scope too. Every other router, including the one their own broadband company supplied, is out of scope, and the answer there is to apply the firewall controls on the device itself with a software firewall. Buying somebody a router as a kindness quietly makes it yours to manage.
Is the firewall built into Windows good enough on a laptop?+
For the purpose the requirements describe, yes. The guidance says most desktop and laptop operating systems now ship with a software firewall and advises turning that on in preference to a third-party firewall application. What it also says is that you must use a software firewall on any device used on untrusted networks, and it gives public wifi hotspots as the example. A laptop that goes to a client site, a hotel or a coffee shop needs its own firewall switched on regardless of what sits in your comms cupboard.
Somebody set up port forwarding years ago for remote access. Is that a problem?+
It is the exact thing the fifth requirement is about: remove or disable firewall rules when they are no longer needed. Inbound rules are also supposed to be approved and documented by an authorised person, with the business reason written down. In practice we find forwards for a camera system that was replaced, a server that was decommissioned, and remote desktop opened for an engineer who left in 2022. None of them are still needed and all of them still work. If you only do one thing after reading this, read that list.
Do you certify Cyber Essentials?+
No. Certification is a self-assessment questionnaire verified by a certification body licensed by IASME, and we are not one. What we sell is the work either side of it: auditing what you have against the five controls, fixing the gaps and keeping the controls in place year-round, which is our Managed Cyber Essentials at 99 pounds per client per month. We do not hold the certification ourselves either, which we say on our own security page rather than leaving you to find out.