Home / Case Studies / Corporate Firewall
Case Study · Industrial · Corporate Firewall · FortiGate

Corporate firewall control for an Australian industrial business: securing the network edge

The business operates in an industrial setting, supporting mining and industrial customers through specialist equipment, service and operational capability. For an industrial business, the firewall protects more than office internet access. It supports communication, business systems, third-party access, remote users, operational coordination, backup pathways, cloud services and the security boundary between the business and external networks.

Inlight IT supports the business with corporate firewall control as part of a managed IT and network security operating model. The focus is practical: maintain a secure, supportable firewall environment, reduce unmanaged access paths, keep perimeter lifecycle risk visible and ensure firewall decisions support daily operations.

CONCENTRIC TRUST ZONES MANAGED EDGE / PERIMETER INSPECTIONPOLICYACCESSSERVICES CORE INDUSTRIAL / CORPORATE FIREWALL MANAGED EDGE / POLICY · ACCESS · SERVICES
Engagement at a glance

An Australian industrial business — corporate firewall inside managed IT

A managed engagement keeping a FortiGate firewall environment secure, supportable and reviewed.

Client
Australian industrial business
Industry
Industrial
Location
Industrial operating environment
Starting point
A mixed industrial technology environment — office systems, operational applications, vendor platforms, remote access, shared devices, local infrastructure and cloud services
Engagement type
Corporate firewall support within a managed IT relationship — a secure and supportable firewall environment protecting users, business systems, remote access, vendor dependencies and operational continuity
Platform
FortiGate firewall with FortiGuard services, IPS, application control, web filtering and DNS security
Outcome
A clearer firewall operating model, with perimeter security, policy control, firmware lifecycle and supportability treated as managed disciplines
Key project stats

A firewall treated as a managed discipline

5
support disciplines

Policy and rule control, remote and third-party access, security services, firmware lifecycle and managed firewall support.

Managed
not just deployed

A deployed FortiGate is configured once. A managed FortiGate is continuously maintained.

Visible
lifecycle risk

Firmware, FortiGuard services and security advisory exposure kept visible before they become urgent.

Reviewed
access pathways

Remote and third-party access pathways reviewed so they remain appropriate to the business need.

Operating context

For an industrial business, the firewall is not only a security boundary. It is part of the operating environment

The business works in a practical industrial setting where technology supports customer response, coordination, administration and access to business systems.

A corporate firewall in that environment has to be reliable, secure and supportable. It needs to handle traffic control, internet access, VPN or remote access, vendor connectivity, security services, firmware lifecycle and future network change without becoming an unmanaged risk.

Inlight IT supports the business with a managed firewall approach that connects perimeter security to the broader operating model.

Why this work mattered

An industrial firewall environment needs control, visibility and lifecycle ownership, not just connectivity

Industrial businesses often run mixed technology environments: office systems, operational applications, vendor platforms, remote access, shared devices, local infrastructure and cloud services. The firewall needs to support that reality without leaving unmanaged access paths or unclear security responsibilities.

01

The firewall needed to support operational access

Industrial users and systems often require access to business applications, vendor services, cloud platforms and remote support pathways. Firewall policy needed to support those requirements while keeping the environment controlled.

02

Remote and third-party access needed clear boundaries

Third-party access and remote support are common in industrial environments. The risk is that access pathways remain broader than intended or are not reviewed after the business need changes. A corporate firewall model needs clear policy, named access pathways and ongoing review.

03

Rules and exceptions could not be left unmanaged

Firewall exceptions often start as practical requirements. Over time, they become risk if they are not reviewed. Legacy and temporary policy entries requiring review all reduce confidence in the environment.

04

Firmware and subscription lifecycle needed ownership

FortiGate protection depends on firmware, FortiGuard services, IPS signatures, application control, web filtering and subscription status. If no one owns those lifecycle points, the firewall becomes progressively less effective.

05

The firewall had to remain supportable

A firewall environment should be understandable to the team supporting it. That means documentation, policy structure, change control, monitoring awareness and escalation pathways.

What Inlight IT delivered

Managed corporate firewall support for an industrial operating environment

Inlight IT supports the firewall environment through practical network security disciplines: policy control, access review, remote access support, security service awareness, lifecycle visibility and escalation.

01

Firewall policy and rule control

Firewall rules kept visible, supportable and aligned to business need, with attention to operational access, unnecessary exposure and policy clarity.

Included
Firewall policy reviewRule change supportNAT and routing considerationsService object reviewAccess-path visibilityRule documentationPolicy improvement recommendations
02

Remote access and vendor connectivity

Access pathways reviewed through a security and operational lens. Remote access and vendor support can be useful, but they need boundaries — managed so they remain appropriate to the business need.

Included
Remote and third-party accessThird-party access reviewMFA and identity alignmentLeast-privilege considerationsAccess expiry and reviewSecure remote support pathwaysZTNA readiness
03

FortiGuard, IPS and security services

A FortiGate firewall is strongest when security services are active, tuned and maintained. FortiGuard services, IPS, application control, web filtering and DNS security are considered as part of firewall management.

Included
FortiGuard subscription awarenessIPS and application controlWeb filteringDNS securitySecurity profile reviewAlert and logging considerationsEscalation for security issues
04

Firmware and lifecycle management

Perimeter lifecycle risk kept visible before it becomes urgent. Firewall firmware and security advisories require active ownership, so the environment does not sit on avoidable exposure.

Included
Firmware version awarenessFortinet security advisory reviewPatch cadence considerationsChange window planningRollback considerationsSubscription renewal awarenessLifecycle risk in service review
05

Managed firewall support

Firewall control included inside managed IT, not left as a disconnected device. The firewall is connected to users, systems, backup, cloud access, remote access and broader network performance.

Included
Managed firewall supportNetwork troubleshootingVendor coordinationService review alignmentEscalation for complex issuesPractical improvement registerDocumentation and supportability
Delivery approach

The path from deployed appliance to managed firewall environment

Select a stage to trace how the firewall moves from deployed appliance to managed environment.

External threat signals

Firewall and edge-device risk is rising because attackers know the perimeter is valuable

Industrial and operational businesses rely on edge devices for connectivity, access and security enforcement. If those devices are misconfigured, unpatched or unmanaged, they become attractive initial access points. For an industrial business, firewall failure or perimeter compromise can affect communication, remote support, business applications, third-party access and the ability to coordinate operational work — edge-device risk is no longer a network footnote. It is an operational continuity risk.

22%

of vulnerability exploitation actions targeted edge devices and VPNs (Verizon 2025 Data Breach Investigations Report).

an almost eightfold rise in edge-device and VPN targeting, up from 3% the previous year.

32

day median remediation time for exploited edge-device vulnerabilities — a long exposure window for internet-facing infrastructure.

12,195

confirmed breaches analysed across 139 countries, from 22,052 incidents.

Verizon 2025 Data Breach Investigations Report
What changed for the client

The business has a more controlled corporate firewall operating model

The engagement gives the business clearer firewall support across policy, access, lifecycle, security services and operational resilience. The firewall is treated as part of the managed environment, not a standalone appliance.

O·01

Policy control

Rules, objects, exceptions and access pathways sit inside a managed review process rather than accumulating without context.

O·02

Access security

Remote support and access pathways can be assessed for scope, identity alignment, business need and future access improvements.

O·03

Perimeter resilience

FortiGuard services, firmware lifecycle and security advisory exposure can be discussed before they become urgent.

O·04

Operational support

Network, VPN, access, security and firewall-related issues can be escalated through the managed IT model.

O·05

Improvement over time

Rule hygiene, policy clarity, security service usage and lifecycle management can improve progressively as the environment changes.

O·06

Drift kept in check

Rules change, applications change, users move and advisories arrive — managed review keeps the firewall maintained rather than drifting.

Net position

A deployed FortiGate is configured once. A managed FortiGate is continuously maintained.

Project outcomes

Firewall management as a discipline, not a one-off configuration

Outcome 01

Industrial operating context

Firewall management aligned to an industrial operating environment.

Outcome 02

FortiGate firewall platform support

FortiGate capability considered across policy, security services, VPN, inspection and lifecycle management.

Outcome 03

Managed ongoing ownership

Firewall operation included in the managed IT relationship.

Outcome 04

Remote and third-party access pathways

Firewall policy reviewed in the context of user, third-party and support access.

Outcome 05

Firmware and subscription risk visible

Firewall lifecycle and FortiGuard service posture included in ongoing review.

Outcome 06

Branch refresh readiness

Where replacement or standardisation is required, controlled refresh planning is part of the service.

Technology and service scope

The work connected firewall policy, access control and perimeter lifecycle ownership

Policy and rule control

7
  • Corporate firewall support
  • FortiGate firewall management
  • Firewall policy review
  • Rule change support
  • NAT and routing considerations
  • Service object review
  • Access-path visibility

Remote and third-party access

7
  • Remote and third-party access support
  • Third-party access review
  • MFA and identity alignment
  • Least-privilege considerations
  • Access expiry and review
  • Secure remote support pathways
  • ZTNA readiness

Security services

6
  • FortiGuard subscription awareness
  • IPS and application control
  • Web and DNS security
  • Security profile review
  • Alert and logging considerations
  • Security advisory awareness

Lifecycle and refresh

6
  • Firmware lifecycle review
  • Patch cadence and change windows
  • Subscription renewal awareness
  • Branch firewall refresh planning
  • Multi-site firewall standardisation
  • Managed service review
Practical next step

Is your firewall environment still secure, supportable and fit for the way the business operates?

We review firewall policy, access and lifecycle, then manage the environment after cutover.

Book a Firewall Review