7 providers that publish a price at all · By location

Compare IT support prices

Managed firewall and network security, and what is still worth guarding at the edge: what managed firewall solutions, a managed firewall service provider, firewall management services, a firewall service provider and firewall service providers actually operate on your behalf, what managed network security, managed network security services and managed network and security services cover, what a network security service provider and network security service providers are selling, what managed utm, managed web security and managed sase bundle together, what best network security means for a business this size, and what a network vulnerability assessment report should contain before you pay for one.

A firewall used to be the whole of security, because everything and everybody was inside one building and the only way in was through the front. That estate has largely gone. Users work from anywhere, files sit in a cloud tenant and mail never touches your network at all, so the firewall now guards a road that a lot of your traffic no longer uses. It is still worth having and worth having somebody manage, but it is worth knowing what it does and does not cover before it is priced as the centrepiece.

What managing a firewall actually means

Four things, and none of them is owning the box. Keeping its firmware current, because an unpatched security appliance is a way in rather than a way of stopping one. Maintaining the rule set, which grows by accretion until nobody knows why half the rules exist. Watching what it reports, which is where most managed firewall services quietly stop. And reviewing the rules periodically against what the business now does. Ask which of the four are in the fee, with hours attached to the third.

What the edge no longer protects

Anything that does not cross it. A laptop on home broadband reaching a cloud tenant never passes your firewall, so nothing it enforces applies. Mail arriving in a hosted mailbox is the same. That is why identity and endpoint control have taken over most of the load: multi-factor everywhere, conditional access, and something watching the device itself. A proposal that answers a remote workforce with a bigger appliance has not noticed where the traffic went.

UTM, SASE and the bundles

A unified threat management appliance is a firewall with filtering, antivirus and intrusion features bundled and licensed together, which is convenient and makes each individual feature harder to evaluate. SASE moves the same controls into a cloud service that users connect to wherever they are, which fits the current estate better and is priced per user rather than per site. Ask what each licence in the bundle is for, whether it is enabled, and who reviews what it blocks.

What a vulnerability report should contain

A scan output is not a report. What you should receive is a list of findings with severity, the specific hosts and services affected, whether each is reachable from outside or only internally, a recommended fix with an estimate of effort, and a clear statement of what was not tested. Without the last two a report is a list of alarms with no path to acting on them, which is how they end up filed and forgotten.

Questions people ask about managed firewall

Do we still need a firewall if we are all cloud?

Yes for any office network and any on-site equipment, but it should not be the centrepiece. Identity and endpoint controls cover the traffic that no longer crosses it.

What is included in a managed firewall service?

It should be firmware patching, rule maintenance, monitoring of what it reports, and periodic rule review. The third is the one most often missing.

What is SASE?

The firewall and filtering controls delivered as a cloud service users connect to from anywhere, priced per user rather than per site. It fits a remote workforce better than an appliance.

How often should a vulnerability scan be run?

Quarterly is common, and the frequency matters less than whether findings get fixed. A report with no remediation effort attached rarely leads to anything.

Sources

Related answers

Get IT support quotesSee what providers publish