Home/Questions/Network, logging and monitoring/Firewall review and firmware
Network, logging and monitoring

How frequently is firewall configuration reviewed and firmware updated?

Edge devices are internet-facing, hold credentials, and sit outside most patch programmes. They have become one of the most exploited categories in the market.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier is asking two things: how often the rule base is reviewed for rules that are no longer needed, and how often device firmware is updated. Both matter and the second has become urgent.

Why it is underwritten

Vulnerabilities in firewalls, VPN concentrators, and remote access gateways have driven a large share of recent intrusions, because they are internet-facing by definition and frequently unpatched. Rule review matters separately, because a rule base that only ever grows becomes permissive over time.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Edge devices sit outside the cloud tenant, so this is attested. The review record is the evidence.

PlatformWhere the setting livesWhat has to be true
FirewallRule base with last-used data and rule ownersUnused rules identified and removed, with each remaining rule attributable. Attested
FirewallFirmware version against the vendor current release and advisoriesCurrent firmware, with a process for emergency updates when advisories are published
Review recordsDated review with findings and changes madeEvidence the review happened and produced changes
Vendor advisoriesSubscription to vendor security advisoriesA route by which you learn about a critical edge advisory within a day rather than a month
AzureCloud firewall and gateway configuration where usedManaged services patch themselves, which is a genuine advantage worth stating
Edge firmware needs the emergency path

Critical vulnerabilities in edge devices are exploited within days of disclosure, sometimes hours. Whatever your general patch window, edge devices need a shorter one and a route that does not wait for the next change window.

What a defensible yes requires

  • The rule base is reviewed at least annually with a record of what was removed.
  • Firmware is current and a process exists for emergency updates.
  • Vendor advisories are subscribed to and monitored.
  • Rules have owners, so review is possible rather than archaeological.
  • Management interfaces on these devices are not reachable from the internet.

How this answer goes wrong

Firmware is treated as infrastructure rather than software, so it is updated when a feature is needed rather than when a vulnerability is published. Devices run versions with public exploits available while the organisation reports a strong patch cadence based on its server estate.

Frequently asked

How often should rules be reviewed?

Annually as a floor, semi-annually for complex rule bases. The value is in removing rules, so a review that changes nothing was probably not a review.

How quickly should firmware be patched?

Critical advisories within days. These devices are internet-facing and actively targeted, which justifies a shorter window than the rest of the estate.

What about cloud-managed firewalls?

The provider patches the platform, which removes the firmware half of the question. Say so; it is a real advantage.

Should the management interface be exposed?

Never to the internet. Compromised edge management interfaces have caused a substantial number of recent intrusions.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture