Skip to content
Singahi

A · Assessment

Firewall and ACL review

A rule-base review of your firewalls and network ACLs: any-any rules, exposed management, missing segmentation and egress, and the shadowed rules nobody owns.

Why it matters

Firewall rule bases accrete over years until nobody can say what any-any rule 27 is for. A review finds the rules that expose the internal network, the management planes open to any source, and the missing egress that lets data walk out.

How we do it

We review the rule base and device configuration against CIS and vendor guidance and least-privilege principles: overly permissive and shadowed rules, management-plane exposure, segmentation between zones, egress filtering, logging and documentation. Each finding cites the specific rule and a fix.

Team credentials: OSCP · CISSP · CISA · CEH · ISO 27001 Lead Auditor.

What you get

  • Executive summary for leadership, technical detail for network engineers
  • Every finding tied to the specific rule, rated by exposure
  • Attack chains showing how permissive rules combine into internal reach
  • A prioritised remediation roadmap with target dates
  • A retest to confirm the findings are closed
  • An attestation letter for your customers and auditors

See the deliverable

See a sample report.

Download a full, anonymised sample report so you can see exactly what you get before you engage. It uses fictional “Sample Client” data, but the structure, depth and rigour are the real thing.

  • An executive summary and a per-finding technical write-up
  • Every finding with a CVSS v4.0 vector and a proof of concept
  • Attack chains showing how issues combine into real impact
  • A prioritised remediation roadmap with target dates

Get the PDF

Sample firewall review report (PDF)

FAQ

Questions, answered

Which firewalls and devices can you review?
The major firewall and network-device platforms, from their configuration export. We work from the rule base and config rather than needing live access.
Do you need live access to the device?
Usually not. A sanitised configuration export is enough for a rule-base review; we agree the approach up front.
Do you retest after we fix the findings?
Yes. A retest is included, so you have confirmation the issues are actually closed.

Why Singahi

What you get with Singahi.

One team, end to end

Compliance, assessment and managed security from one partner that grows with you.

Credentials on the actual team

OSCP, CISSP, CISA, CEH and ISO 27001 Lead Auditor, on every engagement.

AI-assisted and manual

Automation for scale, with people for the judgment that actually matters.

Built to prove it

Evidence your customers, investors and regulators recognise.

Reviewed and updated

Derisk. Build Trust.

Talk to a practitioner.

Tell us what's prompting this, whether a questionnaire, an audit deadline or an investor ask. We reply within four business hours.

What happens next

  1. Tell us the trigger

    A questionnaire, an audit date or an investor ask. The short form or a call both work.

  2. A practitioner replies

    A senior practitioner, not a bot, within four business hours.

  3. You get a scoped next step

    An honest view of what the work involves. No pressure, no theatre.