A firewall isn't something you set up once and forget — but that's exactly how most small businesses end up treating it. It gets configured at install, it works, and nobody has a reason to look at it again. The problem is that "working" and "actually protecting you" quietly drift apart over time, and there's usually no alarm that goes off when they do.

Here's how to tell if that's happened to yours.

1. It was configured once, at install, and never revisited

Threats, traffic patterns, and your own business all change constantly. A ruleset that was correct on day one isn't automatically still correct three years later — it's just still running.

2. Rules exist that nobody can explain the reason for

Every business firewall accumulates rules over time — a vendor needed access, a temporary exception became permanent, someone opened a port to fix one specific problem in 2022. Individually reasonable, collectively they're usually a mess nobody wants to touch for fear of breaking something.

3. You're dealing with cyber insurance and the application asks questions you can't answer

Modern cyber insurance applications increasingly ask specific questions about logging, monitoring, and firewall configuration — not just "do you have a firewall." If those questions are hard to answer honestly, that's a very direct signal of where the gaps are.

4. New employees, devices, or vendors get added without anyone updating the rules to match

If your firewall configuration hasn't changed in step with your team, your vendor list, or the tools you use, it's very likely defending against a version of your business that doesn't exist anymore — while missing the one that does.

5. You wouldn't know if something got through

This is the big one. Without logging and alerting actually configured and reviewed, a firewall can fail silently — meaning the first sign of a real problem is the problem itself, not a warning that gave anyone time to react.

The honest test: if you can't say with confidence when it was last reviewed, or why a given rule exists, an audit is worth doing — not because something is necessarily wrong right now, but because right now is the only time anyone can find out for certain.

What a firewall audit actually involves

Done properly, it's a review of the existing configuration — every rule checked against whether it's still needed, segmentation checked against how the business actually operates today, and logging checked against whether it would actually catch something if it happened. The goal isn't to rebuild everything from scratch; it's to find out what's actually there, close what shouldn't be, and document the rest so the next person doesn't have to start from zero.