A firewall is probably the single most mentioned piece of security equipment in every IT proposal your business has ever received, and also the least explained. Vendors assume you know what it does. Most business owners do not, beyond a vague sense that it is "the thing that blocks hackers."
Here is what a firewall actually does, what it does not do, and how to tell whether the one protecting your business is doing its job or just sitting there.
A firewall is a checkpoint, not a wall
Despite the name, a firewall does not seal your network off from the internet, since your business needs the internet to function, so a true wall would be useless. A firewall is closer to a checkpoint: every piece of data trying to enter or leave your network passes through it, and the firewall decides, based on a set of rules, whether that traffic is allowed.
Those rules can be simple (block all traffic from a specific country, allow email traffic on the standard port, block everything else on that port) or sophisticated (inspect the actual content of traffic for known attack patterns, recognise and block a specific piece of malware trying to communicate with its command server). The sophistication of those rules is the real difference between firewall products, not whether a firewall exists at all.
Basic firewall versus next-generation firewall (NGFW)
A basic firewall, the kind built into most home and small-office routers, checks traffic against simple rules: which ports are open, which IP addresses are allowed or blocked. This stops the crudest, most automated attacks, but it has no idea what is actually inside the traffic it lets through.
A next-generation firewall (NGFW) inspects the actual content of traffic, not just where it is coming from. It can recognise that a file being downloaded matches a known malware signature, that an employee is trying to access a phishing site even though the site itself is not yet blacklisted, or that an application is behaving in a way that suggests it has been compromised, even if the traffic looks technically permitted. NGFWs also typically include intrusion prevention, application-level control (blocking specific apps rather than entire categories of traffic), and centralised logging that a security team, internal or outsourced, can actually use to investigate an incident.
The router your internet service provider gave you almost certainly has a basic firewall built in. It is not a substitute for a properly configured business firewall, in the same way a bicycle lock is not a substitute for a building's access control system. Both are locks. They are not solving the same problem.
What a firewall does not protect you from
This is the part most vendors gloss over, and it matters because it shapes what else you need. A firewall does not stop an employee from clicking a phishing link and entering their password on a fake login page, because that traffic looks legitimate to the firewall. It does not stop malware already inside your network (brought in on a personal USB drive, or through a compromised employee laptop used at home) from moving between machines, unless the firewall is specifically configured for internal network segmentation. It does not protect data that leaves your network legitimately, for example an employee emailing a spreadsheet of customer records to their personal account.
This is why a firewall is described as one layer of a security posture, not the entire posture. It sits alongside endpoint protection (software on individual devices), staff awareness training, and a managed IT provider actively monitoring what is actually happening on your network, not just what a single device is configured to block.
Why this matters beyond just "having one"
A firewall that exists but was configured once, years ago, and never revisited is common, and it is a real gap. Rules accumulate, exceptions get added for a project that ended long ago, and nobody has reviewed the configuration against the business's current size or risk profile. This is not a purely technical detail either: Singapore's Personal Data Protection Act requires businesses to take reasonable security measures to protect personal data they hold, and a misconfigured or absent firewall is exactly the kind of gap that turns a technical oversight into a compliance one.
What We Typically See in Practice
In our experience working with Singapore businesses across education, aviation, and maritime, a few patterns come up repeatedly around firewalls specifically.
The most common pattern we see is a firewall installed correctly at setup, years ago, and never revisited since. Rules accumulate, exceptions get added for a project that ended long ago, and nobody has reviewed the configuration against the business's current size or risk profile.
We also see businesses assume that because they have a firewall, they are covered, without ever having it independently reviewed. A firewall nobody has checked in years is a firewall whose actual effectiveness nobody has verified.
Finally, the businesses that get burned are rarely the ones with no firewall at all. They are the ones with an outdated, unmanaged firewall that gives a false sense of security while quietly failing to catch what a current-generation product would.
Where to go next
- What should your IT provider's SLA actually promise around security incidents? Our IT SLA guide for Singapore businesses explains what to demand.
- Wondering whether this should sit with an internal hire or a managed provider? Our what is a managed service provider guide covers what a good provider actually handles.
- Ready to evaluate a provider? Our 12 questions to ask an MSP covers what a good answer on security sounds like.
If you are not confident your current firewall setup would hold up to real scrutiny, book a free cybersecurity review with Aggasys and we will tell you plainly where the gaps are.
Written by Lee Yang Sean, Aggasys Solutions | sean@aggasys.com | LinkedIn
