Skip to content
FioSec Consulting

Network Security · Case study

From firewall rule sprawl to a rulebase the team can trust

More than half of a manufacturer’s firewall rules had not been used in over two years, and nobody could say what they did. FioSec reviewed every rule, cut the rulebase down to what the environment actually needs, and now helps keep it that way through the client’s monthly change-management meeting.

The situation

The organization

A manufacturing organization whose network and firewall estate had grown through years of plant, office, and system changes. Rules had accumulated faster than they were retired, and staff turnover had taken the context with it.

What prompted it

The Director of Cybersecurity inherited a rulebase nobody fully trusted: more than half the rules had not been used in over two years, and for many of the rest, no one could say what they were for or who owned them. Every unused rule was potential attack surface, every undocumented rule made changes slower and riskier, and cleaning it up in-house kept losing out to daily operations. The Director brought in FioSec to do it properly.

What FioSec did

Each step maps to a layer of the Layered Defence model: vendor-agnostic by design, described by the control it delivers rather than any one product.

  1. Every rule, accounted for

    We reviewed the full rulebase, rule by rule, combining usage data with configuration analysis to classify each one: in active use, unused, duplicate or shadowed by another rule, or broader than what it actually served.

  2. Mapping rules to the business

    Where a rule had no obvious owner, we traced it to the application, system, or partner connection it served, working alongside the IT team, so every surviving rule has a documented purpose instead of institutional folklore.

  3. Staged cleanup, not a purge

    Unused and redundant rules were disabled in stages with rollback windows before removal, so anything that quietly depended on a rule surfaced safely instead of as an outage. The cleanup ran as a controlled project, not a leap of faith.

  4. Tightening what stayed

    Rules that survived but were broader than needed were narrowed to the sources, destinations, and services actually in use, shrinking the attack surface without changing what the business could do.

  5. Keeping it clean

    FioSec now sits in the client’s monthly change-management meeting, reviewing proposed firewall changes so new rules arrive documented, scoped, and owned, and the rulebase stays one the team can trust.

The outcome

The rulebase now contains only the rules the environment needs, each with a documented purpose.

The whole configuration was brought in line with industry best practices, from how rules are documented and scoped through to how new changes are reviewed and approved.

More than half the rulebase, unused for over two years, was safely retired through the staged process.

Firewall changes are now faster and safer to assess, because the baseline is understood instead of feared.

FioSec remains part of the monthly change-management cadence, keeping rule hygiene from sliding back.

Facing something similar?

Tell us where you are today and we’ll help you map the right next step. No obligation.