Ask most IT teams about their firewall and they’ll tell you about the inbound rules: what’s blocked, what’s port-forwarded, who can VPN in. Ask what’s allowed out of the network and the answer is often “everything”, usually followed by a thoughtful pause.
That pause is worth listening to. Modern attacks rarely batter the front door. They arrive by email or a compromised website, and then the malware inside your network phones home: to fetch instructions, to pull down more tooling, to push your data out. Every one of those steps is an outbound connection. If your firewall lets anything talk to anywhere on any port, the attacker’s job is substantially easier.
A ten-second check
Our free outbound security test runs from your browser, inside your network, and checks which outbound paths leave your site unchallenged: web traffic on the standard HTTPS port, and connections on the non-standard ports that malware likes precisely because nobody watches them.
Green across the board on the odd ports is what you want to see. If everything comes back open, your firewall is doing half its job.
What good egress control looks like
You don’t need to strangle the business to tighten the way out. The pattern we deploy for clients is straightforward: allow web browsing through inspection, allow the specific ports your applications genuinely need to the places they need them, and block the rest by default. Pair that with DNS filtering and you’ve removed the easy channels an intruder relies on.
It’s also one of the areas Cyber Essentials assessors and cyber insurers increasingly poke at, so a quick win here helps the paperwork as well as the security.
If the test worries you
Run the test, and if the results aren’t what you hoped, don’t panic: most firewalls can do proper egress filtering, they’ve just never been asked to. Tightening the rules is usually a planned afternoon’s work, not a project. We do it as part of our network services, and if your firewall itself is due for retirement, our FortiGate and Palo Alto end-of-life checkers will tell you in seconds. Or just ask us to take a look.