“We have a firewall.” That is the sentence we hear in almost every initial meeting, and it is almost always true: there is a box in the rack with the name of a security vendor. What follows that sentence is what decides whether the company is protected or not: who configured it, when it was last updated, who reads the alerts, and what happens when one of them is critical. This article compares the two ways of having a firewall — bought and installed, or managed as a service — in terms of cost, risk, and work, without assuming that one is always the right one.
What a firewall does — and what it needs to do it
A modern enterprise firewall filters traffic between the internet and the network, inspects connections for threats, blocks websites and risky categories, terminates VPN connections and separates network segments from each other. To do this well, it needs four things that do not come in the box: company-appropriate configuration (default rules are generic), regular system and threat signature updates, active security subscriptions (they expire and nobody notices), and someone to read the logs and react to alerts. Without these four, the firewall is an expensive router.
Model 1: purchased firewall
The company buys the equipment and the subscriptions, someone sets it up during installation, and from then on it belongs to the company. Advantages: known initial cost, equipment ownership, no monthly fee other than the subscriptions. Problems we frequently see: configuration never reviewed since installation, firmware two or three years out of date, security subscriptions expired months ago (the firewall keeps passing traffic, it just stops inspecting it), rules added “to solve a problem” and never removed, and alerts going to an inbox that nobody checks. None of this is the equipment's fault; it is the absence of management.
Model 2: managed firewall
A firewall — purchased by the company or included in the service — is configured, updated, monitored and operated by an external team, for a monthly fee. Advantages: updates and subscriptions taken care of, alerts read by people and not just reports, periodic review of rules, incident response with defined times, and knowledge that does not leave the company when the internal technician leaves. Disadvantages: monthly cost, and dependence on a supplier — which has to be managed by contract, with an SLA and with the guarantee that the credentials and configuration belong to the company.
Point-by-point comparison
- Costbought has a higher initial cost and low monthly cost (subscriptions); managed has a higher monthly and lower initial cost. At the end of three years the totals converge — the difference lies in what you get for them.
- Updatespurchased relies on someone remembering; managed is part of the service, with scheduled windows.
- Alertsbought generates them; managed handles them. A VPN access attempt alert at 3 a.m. is only useful if someone sees it at 3:05 a.m.
- Configurationbought tends to stay how it was installed; managed is reviewed when the company changes (new office, teleworking, new software).
- Incident responsepurchased depends on finding someone who knows how to work it on that day; managed has written response times.
- Knowledgepurchased is concentrated in one person; managed is documented and in a team.
When a bought firewall makes sense
When the company has an internal IT team with competence in security and time to exercise it — normally above 150-200 workstations —, or when the firewall protects a simple and stable environment, without remote working, without VPNs and without exposed services. Outside of these cases, equipment bought without management gives a false sense of security that the logs do not confirm.
When a managed firewall makes sense
When there is no one dedicated to security within the company; when there is remote working, a VPN or published services; when the company falls under NIS2 or has cybersecurity insurance with continuous management requirements; or when an incident has already shown that alerts were not being read. For the majority of Portuguese SMEs with between 10 and 150 workstations, this is the scenario.
What to demand from a managed firewall
Ensure that the equipment and configuration belong to the company, with administrative credentials handed over in a sealed envelope or digital vault. A monthly report of what has been blocked, updated and changed. Incident response times in writing, with top priority given to security events. Review of the rules at least twice a year. And a clear clause on what happens if the contract ends: the firewall keeps running and the company keeps everything. That is how we work at managed firewalls for businessesthe firewall is installed, configured and monitored by us, with alerts handled by people.
A published example
At FreshDesign, we implemented a next-generation firewall with SSL VPN for remote working, load balancing and failover for two Internet connections, real-time monitoring and alerting, and we took on the ongoing maintenance and support of the security infrastructure — look at the case. At Ventask, with more than 350 sites, the management of firewalls, switches and access points is integrated into the IT Unlimited contract — look at the case.
Frequently Asked Questions
I have already bought a firewall. Can I have it managed?
Yes, in most cases. We assess the equipment, firmware and subscriptions; if it is within the manufacturer's life cycle, we take over management. If it is end-of-life, we propose phased replacement.
Doesn't the ISP router act as a firewall?
It does the basic job of separating the network from the Internet, but it doesn't inspect traffic, filter categories, manage VPNs with MFA, or segment the network. In a company, it's the first thing to replace.
How much does a managed firewall cost?
It depends on the internet bandwidth, the number of users and the services (VPN, filtering, inspection). In IT Unlimited contracts, firewall management is included in the monthly per-user fee; as a standalone service, we provide a quote after a site visit.
Is a managed firewall enough for NIS2?
It is one of the measures, not the only one. NIS2 also requires access management, backups, incident response and training. See our page about NIS2 in Portugal for the full picture.
Want to know the status of your firewall?
We check firmware, subscriptions, rules and alerts, and tell you in writing what is exposed. See our managed firewalls for businesses or call 211 459 950.





































