Sora Yazılım
English
Custom software solutions from Türkiye

What Is a Managed Firewall Service? Who Needs It, What It Covers

A managed firewall service is a contract under which a specialist team takes over the daily operation of your firewall: 24/7 monitoring, controlled policy change management, patch and firmware updates, log review, incident response, regular reporting and license tracking, all under a defined SLA. The device stays in your organization; the operational burden and most of the responsibility move to the provider.

What Is a Managed Firewall Service?

A managed firewall service means that a contracted expert team, rather than your own staff, runs the firewall day to day: monitoring, rule changes, updates, log analysis and incident response. Hardware and licenses remain your property; what changes is who manages the device, through which process and under which commitments.

Most organizations consider a firewall project finished the day the device is delivered and the internet works. A firewall, however, is not a "set and forget" appliance. A rule is added when a new server goes live, a VPN account is closed when an employee leaves, firmware is upgraded when the vendor announces a critical vulnerability, an IP is blocked when a repeated scan shows up in the logs. When this work is not done, the device keeps running, but the level of protection quietly declines.

The risk usually lies less in choosing the wrong product than in operating the right product badly or incompletely: forgotten temporary rules, postponed firmware upgrades, logs nobody reads. That is precisely the problem a managed firewall service solves: it moves operational discipline out of one person's memory and into a defined process.

The boundaries of the service are drawn in the contract: which devices are in scope, during which hours service is provided, who approves changes and which compliance reports are produced. Until these four questions are answered, "managed firewall" means something different at every provider.

Who Needs a Managed Firewall Service?

A managed firewall service is needed by organizations that have no dedicated team to watch the firewall outside business hours and follow vulnerability advisories, and by those with multiple branches, remote staff or regulatory obligations such as Turkey's KVKK data protection law and Law 5651. Organizations with a fully staffed security operations center (SOC) are usually better served by a co-managed model.

In our field experience, the clearest signals of need are these:

  • The IT team consists of one or two people who are responsible for servers, printers, user support and the firewall at the same time. The firewall is the least urgent yet most critical item on the list and gets postponed continuously.
  • Nobody knows when the last firmware update was applied. Vendor security bulletins reach no one, or are read but never acted on.
  • The rule base has grown over the years, and "temporary" rules whose author and purpose nobody remembers have become permanent. Our guide to firewall rule cleanup and policy auditing is a separate starting point for diagnosing and fixing this.
  • Logs are collected, but nobody looks at them. The difference between keeping logs and reviewing logs becomes visible only when an incident happens.
  • There are several branches or sites, each with its own device, its own policy and its own license expiry date.
  • Threat signatures stopped updating because a license expired, and the organization did not notice until something went wrong.

If three or more of these signals apply to your organization, the problem is operational capacity rather than technology, and the fix is a different operating model rather than a new device.

What Does a Managed Firewall Service Cover?

A managed firewall service covers seven core items: continuous monitoring, policy (rule) change management, patch and firmware management, log review, security incident response, regular reporting and license/subscription tracking. Scope may be narrower at some providers, so when comparing quotes you should ask for the frequency and deliverable of every item.

Scope itemWhat is done?Typical frequencyDeliverable to the customer
MonitoringDevice availability, CPU/memory/session load, tunnel status, HA health and critical alertsContinuous (8x5 or 24/7 depending on service hours)Alert notifications, monthly availability summary
Policy change managementAdding, editing and removing rules through a request-approve-implement-verify-record cycleOn request, by priority classChange record with justification and rollback note
Patch and firmwareTracking vendor bulletins, version planning, upgrades in maintenance windows, backup firstImmediately for critical vulnerabilities; periodic for planned releasesUpgrade report, configuration backup
Log reviewReviewing traffic, threat, VPN and administrator logs; flagging abnormal patternsDaily/weekly; immediately during incidentsFindings list, recommended actions
Incident responseCutting suspicious traffic, blocking IPs/domains, disabling compromised accounts, collecting evidenceWithin the response time defined in the SLAIncident report with root cause and permanent fix
ReportingThreat summary, top blocked sources, bandwidth, policy changes, compliance evidenceMonthly; on request for compliance auditsExecutive summary and technical appendix
License trackingTracking subscription expiries such as FortiGuard/FortiCare, renewal planning, preventing service gapsContinuous; alerts 90/60/30 days before expiryLicense calendar, renewal recommendation

Each row in this table becomes a commitment only when its frequency and deliverable are written down, not when a provider says "we do that". "Log review", for instance, may mean an automated alert email at one provider and a weekly human review with a findings list at another. License tracking is often overlooked, yet when a subscription lapses the antivirus, IPS and web filtering signatures stop updating, and because the device visibly keeps working nobody notices.

In-House, Managed and Co-Managed: A Scope Comparison

Firewall management can be run under three models: in-house (all responsibility with your own team), fully managed (monitoring, changes and response with the provider, approval with you) and co-managed (routine operation with the provider while you keep console access and emergency authority). The choice depends on the depth of expertise in your organization and its capacity outside business hours.

Scope itemIn-houseFully managedCo-managed
MonitoringYour tools and staff; usually unattended after hoursProvider's monitoring platform, with a 24/7 optionProvider monitors, alerts reach both sides
Policy changesYour team implements; record-keeping depends on individualsProvider implements, you approveRoutine changes with the provider, urgent ones may also be made by you
Patch and firmwareYou track and applyProvider plans and applies in maintenance windowsProvider plans; you approve the window
Log reviewUsually only after an incidentRegular review and findings reportProvider reviews, you can run your own queries
Incident responseYour team; limited experience and hoursSLA-backed response, you are informedFirst response with the provider, decisions shared
ReportingPrepared manually on requestStandard monthly report packMonthly report plus your own dashboards
License trackingProcurement or IT's calendarProvider keeps the calendar, proposes renewalProvider reminds, you decide
Console accessEntirely yoursWith the provider; read-only access for you is recommendedBoth sides, with role-based permissions
Best-fit profileOrganizations with a dedicated security team and SOCSMBs and multi-branch organizations without a dedicated security teamOrganizations with experts but no after-hours capacity

In the co-managed model, the critical issue is change collision: if both sides can change rules on the same device, who changed what and when must be kept in a single system of record, and configuration backups must be taken after every change. Otherwise one side unknowingly breaks what the other just fixed.

How Do SLA Models and Change Management Work?

A managed firewall SLA should contain two separate commitments: a response time for change requests (with distinct classes for emergency, standard and project changes) and a detection and response time for security incidents. A contract that promises only device availability is selling infrastructure management, not security management.

Common industry practice is to divide change requests into three classes:

  • Emergency change: made to stop an active attack or to restore business-critical access. A response within hours is expected; approval may follow afterwards, but the record is always kept.
  • Standard change: routine requests such as access to a new server, a new VPN user or opening a port for an application. Planned on a business-day scale and passed through the approval matrix.
  • Project change: major firmware upgrades, integrating a new branch, architectural changes such as SD-WAN or ZTNA. Planned separately and usually tied to a maintenance window.

For security incidents, the two metrics to ask about are mean time to detect (MTTD) and mean time to respond (MTTR). If a provider does not commit to these two in writing, "24/7 monitoring" tells you that an alert will be generated, not that someone will act on it. For a reference framework on the firewall policy lifecycle, see NIST SP 800-41 Rev. 1.

Change management itself is a five-step cycle: request (who, which source, which destination, why, for how long), technical review (conflicts with existing rules, overly broad access, least-privilege principle), approval (an authorized person on your side), implementation and verification (backup, write the rule, test) and record (with justification and a rollback plan). The provider should tie this cycle to a ticketing system; changes that happen "because someone called" leave no evidence during an audit.

The contract should also define the escalation chain (who, after how many minutes, through which channel), the reporting cadence and the service credit applied when a commitment is missed. A provider that refuses to attach credits is telling you how much confidence it has in its own response times.

Variables That Shape Scope and Cost

The cost of a managed firewall service is determined by the number and class of devices, service hours (8x5 or 24/7), monthly change volume, log retention period, compliance reporting needs, number of sites and high-availability (HA) design. Two organizations with the same device can pay very different fees because of these variables, which is why quotes are compared on scope.

  • Device count and class: managing one headquarters device is a different workload from managing ten devices in ten branches. Device class (an entry-level desktop model versus a data-center model) also determines policy complexity. If the model has not been chosen yet, our firewall selection guide for SMBs explains the sizing criteria.
  • Service hours: the difference between 8x5 and 24/7 monitoring is the cost of people on call outside business hours. According to the Sophos Active Adversary Report 2026, 88 percent of ransomware payloads were deployed outside the target's business hours, so this should be the last item you economize on.
  • Change volume: a few rule changes per month and a software company that launches a new application every week cannot be priced the same. Packages usually define a monthly change quota.
  • Log retention and analysis: keeping logs on the device is one thing; long-term storage and regular analysis on a central platform such as FortiAnalyzer is a separate item. Retention obligations under Law 5651 and KVKK may make it mandatory; verify the current legislation and official guidance.
  • Compliance reporting: producing regular evidence for KVKK technical measures, internal audits or customer audits requires additional work.
  • License and subscription status: the FortiGuard bundle and FortiCare support level are separate items outside the service, but the managed service takes over tracking and renewal planning for them.
  • HA and architecture: active-passive pairs, SD-WAN, multiple WAN links or ZTNA designs increase both operational and change complexity.

"Fixed monthly fee" quotes obtained before these variables are settled either hide the scope or turn into extra charges at the first incident. The right order is to write the scope first and ask for a price second.

Sora Yazılım's Managed Firewall Scope

Sora Yazılım, as an independent Turkey-based solution partner, delivers monitoring, policy change management, patch and firmware planning, log review, incident response, monthly reporting and license tracking for firewalls, FortiGate first and foremost, within a single service framework. Scope is set up as fully managed or co-managed depending on your existing team.

In our projects we structure the service as follows:

  • Monitoring: availability, resource usage, VPN tunnels and HA state of FortiGate devices are watched continuously; critical alerts follow a defined escalation chain.
  • Policy change management: every request is ticketed, reviewed under the least-privilege principle, implemented after your approval and recorded with its justification. The rule base is audited periodically.
  • Patch and firmware: vendor bulletins are tracked; critical vulnerabilities are handled quickly, planned releases in maintenance windows with a configuration backup taken first. The operational details are covered in our article on FortiGate maintenance and repair.
  • Log review: logs are reviewed regularly in FortiAnalyzer or your existing log platform; findings such as repeated scans, unusual country traffic and failed administrator logins are reported.
  • Incident response: cutting suspicious traffic, disabling accounts and collecting evidence are done within the time defined in the SLA; every incident is closed with a root cause and a permanent measure.
  • Reporting: a monthly executive summary (threats, availability, changes, license status) and compliance evidence appendices on request.
  • License tracking: FortiGuard and FortiCare expiry dates go into a calendar, renewal options are presented in advance and interruptions to signature updates are prevented.

Together with regular firewall maintenance, the managed service can be run by the same team as our DevOps and infrastructure management service covering your servers and network, so that firewall, servers and backup are unified under one operational discipline. If you only need a second opinion, starting with contract-free FortiGate consulting is also possible.

How Do You Plan the Transition?

Moving to a managed firewall service is planned in four steps: taking an inventory of current devices, rules and licenses; cleaning up and documenting the rule base; migrating from the old device to a new platform if necessary; and then writing down the approval matrix, escalation chain and reporting calendar. The first thirty days are reserved as an observation period.

  1. Discovery and inventory: which devices exist, on which firmware, which licenses expire when, which rules were written by whom and why. The output of this step is the service scope itself.
  2. Rule base cleanup: unused, shadowed and overly broad rules are removed before handover; every remaining rule gets an owner and a justification. We describe the method step by step in the rule cleanup guide.
  3. Migration if needed: if the device is out of vendor support or lacks capacity, the transition is planned before the service starts. Our migration plan from a legacy firewall to FortiGate is a roadmap for executing that transition without downtime.
  4. Process design: the approval matrix (who approves which change), escalation chain, maintenance windows, reporting calendar and console access roles are written down. In the co-managed model, the single system of record that prevents change collisions is set up here.
  5. The first thirty days: alert thresholds are tuned to your traffic, false positives are weeded out and the first monthly report is read together to calibrate expectations.

Frequently Asked Questions

Who owns the device in a managed firewall service?

In most models the hardware and licenses are your property; the provider only takes over operation. Some providers also offer the device under a rental model. The contract should clearly state device ownership, who owns the configuration backups and the handover terms when the service ends.

What is the difference between a managed service and firewall maintenance?

Maintenance covers firmware, backups and general health checks through periodic visits or remote sessions. A managed service adds continuous monitoring, change management, incident response and an SLA commitment. Maintenance is periodic; a managed service is continuous.

Do we need a managed service if we have our own IT team?

If you have a team, the co-managed model fits: routine operation, after-hours monitoring and firmware planning stay with the provider, while you keep console access and critical decisions. Your internal team is freed from daily rule requests and can focus on projects.

Is firewall management enough for KVKK and Law 5651 compliance?

Not on its own, but it covers a significant part of the technical measures: access control, logging, up-to-date software and incident records. For obligations such as log retention periods and timestamps, verify the current legislation and official guidance; the legal assessment must be done separately.

Does the provider need our approval before making a change?

Yes for standard and project changes; the approval matrix is defined in the contract. For emergency changes, such as stopping an active attack, the provider may act first and inform you afterwards, but the limits of that authority must also be in writing.

Does the firewall keep working when the license expires?

The device keeps passing traffic, but antivirus, IPS, web filtering and application control signatures are no longer updated, so protection ages quickly. The license tracking item of a managed service exists precisely to prevent this silent gap.

Conclusion

A managed firewall service turns the firewall from a purchased device into an operated process. Defining scope with seven items (monitoring, policy change management, patch and firmware, log review, incident response, reporting, license tracking), choosing the in-house, fully managed or co-managed model that matches your capacity, and demanding written change and incident response times in the SLA are the three essential steps to selecting the right provider.

To assess your current firewall setup together and receive a scope-based quote, you can schedule a free discovery call with Sora Yazılım; we work through the inventory and rule analysis with you and report impartially on which model fits.

Need help with the topics in this post?

Schedule a free discovery call with Sora Yazılım — we'll propose a concrete roadmap.

WhatsApp Support