NETWORK SECURITY
Network security starts with knowing what can talk to what
A firewall at the internet connection is useful, but it does not make an entire business network secure.
Most Sydney offices now connect far more than staff computers. There are wireless access points, printers, meeting room equipment, phones, cameras, building systems and cloud services. Remote workers and vendors may also need access. If every device sits on one flat network, a problem in one area has a clearer path to the rest.
Good network security starts with a simple question for Sydney businesses. Which systems need to communicate, and which should be kept apart?
That question drives firewall rules, network segmentation and monitoring. For buyers comparing network security Sydney providers, the practical test is whether those controls have an owner and a review process. It also gives the business a way to review changes rather than letting years of temporary exceptions become permanent access.
The Australian Signals Directorate recommends segmenting networks at the lowest practical level and using host-based and network-wide measures together. Its guidance also says those controls should be centrally monitored. ASD network segmentation guidance
For Milnsbridge clients, Managed FortiGate is the managed firewall layer and is scoped separately from the base IT support plans. It covers firewall configuration, firmware updates, VPN support, monitoring and documented change control. The firewall is part of a wider network design rather than a box installed once and forgotten.
CONTROL THE TRAFFIC
Four parts of a maintainable network
Managed firewall
Configuration, updates, VPN support and monitoring need an accountable owner.
Segmentation
Separate staff, guest, connected equipment and management traffic according to business need.
Endpoint coverage
Network controls and SentinelOne endpoint protection address different parts of the same risk.
Alert response
Monitoring has value only when someone validates events and records the outcome.
PRACTICAL GUIDANCE
A business router and a managed firewall do different jobs
An internet router connects the office to the provider. It may include basic firewall functions and a simple wireless network. That can suit a home office or a very small environment with little complexity.
A growing business usually needs more control. It may have multiple sites, guest WiFi, remote access, servers, business applications and compliance obligations. Those requirements call for policy decisions that a default router configuration cannot make on the business's behalf.
A managed firewall can apply rules based on source, destination, service and risk. It can support site-to-site and SSL VPN connections. Security profiles can inspect traffic, and event logs can be reviewed when something unusual happens. Firmware and rule changes can be scheduled, documented and tested.
The word managed matters. Hardware alone does not review old rules, investigate alerts or confirm whether a temporary vendor connection should still exist. Milnsbridge manages FortiGate configuration and monitoring under change control so each adjustment has an owner and a reason.
Businesses comparing firewall services should ask:
- Who reviews firewall rules and how often
- How firmware updates are tested and scheduled
- Which alerts are monitored and who responds
- How remote access is approved and removed
- Whether configuration changes are documented
- What reporting the business receives
A useful answer should describe an operating process. A product name without ownership or follow-through leaves the hard part unresolved.
PRACTICAL GUIDANCE
Network segmentation limits unnecessary access
Segmentation divides a network into controlled zones. The goal is to let each group reach what it needs while blocking traffic that has no business purpose.
A professional services office might separate staff devices, guest WiFi, printers, meeting rooms and management interfaces. A warehouse may add scanners, cameras and operational equipment. A multi-site business may control traffic between locations instead of treating every site as one trusted space.
ASD's networking guidance says network access controls should limit traffic within and between segments to what the business requires. ASD Guidelines for Networking
The design should remain practical. Dozens of poorly documented segments can create support problems and encourage broad exceptions. The right level depends on business risk, device types and who maintains the environment.
Four common zones are a sensible starting point.
Staff devices
Managed computers used for everyday work need access to approved business services. They should not automatically have administrative access to network equipment.
Guest access
Visitors need internet access, not a path to internal files, printers or management interfaces. Managed WiFi can provide separate staff and guest wireless networks with clearer ownership.
Connected equipment
Cameras, printers, meeting room devices and other connected equipment often need limited destinations. Keeping them separate reduces the trust given to devices that may receive updates less consistently.
Management access
Firewall, switch and wireless management interfaces should be available only to authorised administrators through controlled paths. General staff traffic has no reason to reach them.
Segmentation does not replace endpoint security. A compromised laptop still needs detection and response. SentinelOne endpoint protection covers the device layer while firewall rules and network controls govern traffic between systems.
PRACTICAL GUIDANCE
Monitoring turns network activity into something usable
A network can pass traffic all day and still hide a problem. Monitoring gives the support team evidence about device health, security events and unusual behaviour.
Useful monitoring starts with expected behaviour. Which links should be active, which devices normally communicate and what capacity does the office require? Without that baseline, every alert looks equally urgent or equally harmless.
Managed FortiGate monitoring covers threat alerts, device health and traffic events. FortiGate logs also help investigate questions that are difficult to answer from an endpoint alone. A support team can review when a connection began, which rule allowed it and whether the destination was expected.
Monitoring should lead to action. An alert that nobody owns is just another message in a queue.
A practical response process includes:
- Confirm the affected device, account or network segment.
- Check whether the activity matches an approved business process.
- Contain traffic when the risk justifies it.
- Preserve enough evidence for investigation.
- Record the outcome and any required rule or design change.
When an event becomes a real security incident, the Milnsbridge incident response service provides triage, containment, recovery and follow-up work.
PRACTICAL GUIDANCE
Firewall rules need an owner and an expiry path
Firewall rule sets often grow through reasonable requests. A vendor needs access during a project. A new application needs a port opened. A staff member needs remote access while travelling.
The risk appears when nobody closes the loop.
Every exception should record who requested it, what it enables and when it should be reviewed. Broad rules such as any source to any destination should be avoided unless there is a documented and temporary reason. Rules should use the narrowest practical source, destination and service.
Documented change control also helps during troubleshooting. If a service stops working after a change, the support team can identify what moved and reverse it safely. If an unfamiliar rule appears, there is a record to test against.
Milnsbridge's Managed FortiGate service includes firewall rules, NAT policies and security profiles managed under change control. Firmware updates are reviewed and scheduled rather than applied without testing. This reduces the choice between leaving a device outdated and taking an uncontrolled production risk.
PRACTICAL GUIDANCE
Remote access should not bypass the network design
Remote work changes where a user connects from, but it should not remove normal access controls.
A VPN can provide an encrypted path into the business network. That path still needs boundaries. A remote user should reach the systems required for their role rather than receiving unrestricted access to every internal segment.
Multi-factor authentication reduces the risk that a stolen password is enough to open remote access. Duo MFA supports managed rollout and ongoing administration. The VPN article explains the wider remote-access decision in more detail. VPN and secure remote access for Sydney businesses
Access should also be removed promptly when a staff member or contractor leaves. A technically secure VPN account is still a problem if it belongs to someone who no longer has a business need.
FACTS AND FIGURES
Four network security figures worth understanding
is Milnsbridge's published average phone answer time. It measures phone queue speed, not firewall detection or incident containment. Metrics methodology
is Milnsbridge's first-contact resolution rate across support tickets. It is a service desk measure rather than a claim about preventing cyber incidents. Metrics methodology
is the Essential Eight patching timeframe commonly applied to critical vulnerabilities when exploitation is occurring or public proof of concept exists. The exact treatment depends on the system and current ASD guidance. ASD patching applications guidance
should be accountable for each firewall change, remote-access exception and unresolved monitoring alert. This is an operating principle, not an industry statistic.
PRACTICAL GUIDANCE
What a network security review should produce
A useful review identifies internet connections, network devices, wireless networks and important segments. It should show which remote-access paths exist, who owns them and how alerts are handled. It should separate urgent exposure from design improvements that can be planned.
For a Sydney business, the review should answer four questions.
- What is connected
- What can communicate
- What is being monitored
- Who acts when something changes
If those answers are vague, buying another security product will not fix the ownership gap.
FAQ
Common questions about network security
Does a small business need network segmentation?
Many small businesses benefit from basic separation between staff devices, guests, connected equipment and management interfaces. The design should stay manageable and reflect actual business risk.
What is the difference between a router and a managed firewall?
A router connects networks and may provide basic firewall functions. A managed firewall adds policy management, security inspection, logging, updates, monitoring and an accountable service process.
How often should firewall rules be reviewed?
Review frequency depends on the environment, but temporary access should have an expiry or review date. Material business and network changes should also trigger a review.
Can guest WiFi access internal systems?
It should not by default. Guest access normally needs internet connectivity only and should be separated from internal business devices and management interfaces.
EXPLORE MORE
Related Milnsbridge resources
Managed FortiGate
Managed WiFi
Endpoint protection
Incident response
NEXT STEP
Build network security around clear ownership
Network security works when the rules match the business and somebody maintains them.
Milnsbridge provides Managed FortiGate configuration, firmware updates, VPN support, monitoring and documented change control for Sydney businesses. It sits alongside managed WiFi, endpoint security, identity controls and incident response.
If your firewall rules have grown without review, guest and staff traffic share the same network, or alerts do not have an obvious owner, start with a network review.
Milnsbridge answers support calls in 20 seconds on average and resolves 87 percent of tickets on first contact. Talk to Milnsbridge about your network security setup.
GET IT RIGHT
Talk through your requirements with the Sydney team
Milnsbridge answers support calls in 20 seconds on average and resolves 87% of tickets on first contact. Talk to our Sydney team about network security, firewall management and monitoring.
About the Author
Adrian Weir
Adrian Weir is the Managing Director and founder of Milnsbridge Managed IT Services, with over 30 years of global IT experience spanning Telstra, Citibank, Unilever, and hundreds of Sydney SMBs. A Microsoft Partner since 2002, Adrian leads a team of IT specialists delivering responsive, business-focused managed IT support across Greater Sydney.
Meet the Milnsbridge Team
