What Is a Firewall? A Plain-English Guide for Small Businesses
A firewall is the guard on the boundary between your business and the internet, deciding what traffic is allowed in and out. This article explains the difference between the firewall in your router, the software firewall on each device, and next-gen firewalls — and why a properly configured firewall is one of the five core Cyber Essentials controls every UK small business should have in place.
Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.
The guard on your digital front door
Imagine your business network as a building. Data flows in and out all day — emails, web pages, files, video calls. A firewall is the security guard standing at the door, checking what’s allowed through and turning away anything that shouldn’t be there. It’s one of the oldest ideas in cyber-security, and one of the most important, precisely because it works quietly at the boundary before a threat ever reaches your computers.
Despite the slightly intimidating name, the concept is simple. A firewall follows a set of rules about what traffic is permitted. Anything that doesn’t match the rules gets blocked. The art is in setting those rules sensibly — and, crucially, in not leaving the firewall on the factory defaults it arrived with.
A firewall doesn’t need to be clever to be valuable — it needs to be switched on, configured on purpose, and not left on the settings it came with.
The three kinds of firewall you’ll come across
The word “firewall” covers a few different things. For a small business, these are the three that matter.
1. Your router’s firewall
The broadband router in your office almost certainly has a firewall built in, and it’s usually switched on out of the box. This is your first line of defence, sitting between your whole network and the internet. It’s genuinely useful — but it comes with two big caveats that trip businesses up constantly:
- The admin password is often never changed. Routers ship with a default password that’s printed in the manual and known to attackers. If you haven’t changed it, the firewall guarding your network can be walked straight past.
- The firmware is often never updated. Routers need security updates just like any other device. An out-of-date router is a known weak point.
For a very small business, a properly secured router firewall is a reasonable starting point. But treat it as the floor, not the ceiling.
2. Software firewalls on each device
Every Windows PC and Mac has its own built-in firewall running on the device itself. This protects the individual machine, which matters enormously the moment a laptop leaves the office. A device firewall doesn’t care whether you’re in the building or in a coffee shop — it guards that one computer wherever it goes.
The key point: leave these switched on. It’s surprisingly common for someone to turn a device firewall off to fix a one-off problem and never switch it back on. Under Cyber Essentials, these host firewalls are expected to be active.
3. Next-generation firewalls
At the top end sits the next-generation firewall, or NGFW. This is a dedicated piece of kit (or a cloud service) that does far more than simply allow or block connections. It can look at the actual content of traffic, block known-malicious websites, detect intrusion attempts, and make decisions based on which application is being used rather than just which door it’s knocking on.
For most small firms, a next-gen firewall isn’t something you buy off a shelf and configure yourself — it comes as part of a managed IT arrangement, set up and monitored by people who do it every day. If your business handles sensitive client data — think accountants or solicitors — this level of protection is well worth discussing.
Why a firewall is a Cyber Essentials control
Cyber Essentials is the UK government-backed scheme that sets out five basic controls every organisation should have. A firewall is one of them — and for good reason. The other four cover things like secure settings, access control, malware protection and keeping software updated, but the firewall is the one that governs your boundary with the outside world.
Certifying to Cyber Essentials means demonstrating that your firewalls are in place, that default passwords have been changed, and that you’re not exposing services to the internet that don’t need to be. It’s a low bar in the best sense: achievable for any small business, and it blocks the large majority of common, opportunistic attacks. We cover the whole scheme in Cyber Essentials explained for UK small business.
Setting a firewall up sensibly
You don’t need to become a network engineer, but a few principles will keep you on the right side of sensible:
- Change every default password. On the router, on any dedicated firewall, on everything. This is the single most common firewall failing.
- Block by default, allow on purpose. A good firewall blocks everything and only opens the specific doors your business actually needs. If you’re not sure why a door is open, it probably shouldn’t be.
- Keep the firmware updated. Firewalls are software too, and they need patching.
- Don’t expose things to the internet needlessly. Remote-access services left open to the whole world are a favourite target. If staff need remote access, do it through a secure method, not by flinging a door open.
- Keep device firewalls on. Every laptop and PC, always.
The firewall gap for remote workers
Here’s a catch that the shift to home and hybrid working has made important. Your office firewall protects the office. A member of staff working from their kitchen table is behind their own home router, not yours — so none of your office protections reach them.
That’s why remote staff should route their work traffic through a VPN, which creates a secure, encrypted tunnel back to your systems and keeps their traffic private even on untrusted networks. A reputable service like Proton VPN does this without the complexity of older corporate setups. Pair the VPN with the device’s own software firewall left switched on, and your home workers get sensible protection wherever they are.
The bottom line
A firewall isn’t glamorous and it isn’t clever, but it’s foundational. Get the basics right — change the defaults, keep it updated, block what you don’t need, and don’t forget your remote staff — and you’ve dealt with a whole category of threats before they get anywhere near your data.
If you’re not certain how your firewalls are configured, or whether you’d pass Cyber Essentials today, that’s exactly the kind of thing we check as part of our cyber-security service. Talk to us and we’ll give you a straight answer about where you stand.
Frequently asked questions
Does my business need a firewall if I already have antivirus?
Yes — they do different jobs. Antivirus checks for malicious files and programs on a device. A firewall controls the traffic coming in and out across your network boundary, blocking unwanted connections before they ever reach a device. You want both. In fact, both are required controls under Cyber Essentials.
Isn't the firewall in my broadband router enough?
For a very small business it can be a reasonable start, provided the default admin password has been changed and it's kept updated — two things that are astonishingly often missed. As you grow, or if you handle sensitive data, a dedicated business firewall gives you far more control and visibility. The router firewall is a floor, not a ceiling.
What is a next-gen firewall?
A next-generation firewall (NGFW) does everything a traditional firewall does but adds smarter features: it can inspect the actual content of traffic, block known malicious websites, spot intrusion attempts, and filter by application rather than just by port. For most small firms this comes as part of a managed service rather than something you buy and configure yourself.
Do firewalls protect staff who work from home?
Not automatically. A home worker sits behind their home router, not your office firewall, so your office protections don't extend to them. That's why remote staff should use a VPN to route their work traffic securely, keep the software firewall on their device switched on, and follow the same standards as everyone in the office.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.