Build. Scale. Transform.
Blog · Network & Infrastructure

The Firewall Audit We Run Before Touching Anything Else

Most firewalls we inspect are still running close to factory defaults years after installation. Here's the specific checklist we go through before recommending a single configuration change.

2026-03-30 7 min read DAB Inventive Team
The Firewall Audit We Run Before Touching Anything Else

A firewall on default settings is barely better than no firewall, and it's a more common state than most businesses would guess. We've opened firewall configurations at established, otherwise well-run businesses and found default admin credentials still active, rules nobody remembers adding, and logging turned off entirely because it was never turned on in the first place. Before we recommend a single change, we run the same audit every time.

Step one: who can actually get in, and how

We start by mapping every open port and every rule that allows inbound traffic, and for each one, we ask a simple question: is this still needed, and does whoever set it up remember why. A remote access rule opened for a vendor project that ended two years ago is a live vulnerability sitting untouched, and we find these constantly. Anything that can't be explained gets flagged for removal, not just noted.

Step two: default credentials and unused accounts

This sounds basic because it is, and it's also one of the most common findings we have. Default admin logins, shared accounts nobody's rotated a password on in years, and former employees or vendors who still technically have access. None of this requires sophisticated tooling to find. It requires actually checking, which is the part that gets skipped.

Step three: what's actually being logged, and does anyone look at it

A firewall generating logs nobody reviews is functionally the same as a firewall with logging turned off, just with worse false confidence attached. We check whether logging is enabled at a useful level of detail, whether logs are retained long enough to matter during an incident investigation, and whether any alerting exists for the events that should actually trigger a human looking at something, not just noise nobody could realistically monitor.

Step four: segmentation, or the lack of it

A flat network where a compromised guest Wi-Fi device sits on the same segment as your finance system's database server is a design problem no firewall rule alone fixes. We check whether guest access, IoT and smart-office devices, and core business systems are actually separated at the network level, since a segmented network turns "one compromised device" into a contained incident instead of a wide-open door to everything else on the network.

Step five: does the configuration match the actual risk profile

A five-person consultancy and a business processing financial or health data need genuinely different levels of protection, and we've seen both directions go wrong: businesses over-securing a low-risk setup in ways that create friction without meaningfully reducing risk, and businesses handling sensitive data running consumer-grade protection because nobody assessed what was actually at stake. This step is where we align configuration to what the business genuinely needs to protect, not a generic checklist applied regardless of context.

What happens after the audit

Every finding gets written up and ranked by actual severity, not a vague list of concerns. Some fixes are a five-minute configuration change. Some require a real conversation about budget and risk tolerance before deciding how far to go. Either way, you get a document you can act on, not just a verbal "looks fine" that leaves you exactly where you started.

If it's been over a year since anyone actually reviewed your firewall configuration rather than just trusting it's still doing its job, that's usually a sign it's overdue, regardless of how the business has been running otherwise.

Let's talk

Have a project this touches on?

Tell us what you're building or running today. We'll give you a straight answer, not a sales pitch.