According to The State of Ransomware 2026, a survey by security company Sophos of 2,158 IT decision-makers at companies hit by a ransomware attack — a program that scrambles a company's files and demands payment to unlock them — across 17 countries, the firewall — the equipment that filters what goes in and out of the company network — was the entry point in 21% of attacks that started with an exploited flaw, a stolen password, or an attempt to guess a password through trial and error. That makes it the third most common door in, behind an exposed internet-facing system (38%) and an employee's device (30%).
The firewall sits in a different spot than the other three. It lives at the network edge, between the company and the internet, and sees everything crossing that line. When an attacker gets through it, the damage tends to be bigger: according to the same survey, 59% of ransom demands in attacks that started with an exploited flaw on the firewall were $1 million or more, compared to 48% of all demands recorded in the study.
That gap is what matters to whoever signs off on the IT budget. The same box bought to be the first line of defense can, on its own, become the reason a ransom demand comes in higher. And at most small and mid-sized companies, no one can say with any confidence when someone last actually looked at what is configured inside it.
The Box No One Revisits
A firewall usually arrives the easy way: the vendor installs it, tests it, opens a few rules "just for now" so the test works, and leaves. The trouble is that "just for now" rarely gets a closing date. The rule stays open, the firmware stays at install-day version, and the only time anyone comes back to it is after something has already broken — never before.
Sophos's data shows why that habit is expensive. Among attacks that hit the firewall, a compromised credential was the most common cause (41%), followed by an exploited flaw on the device itself (33%) and a password guessed through trial and error (26%). And the firewall is the preferred target for that last method: among the four device types measured in the survey, it was targeted by trial-and-error password attempts at the highest rate, 44% — well ahead of exposed systems, remote-access networks, and other network devices.
The trial-and-error pattern has a simple explanation: if no one limits how many times someone can get a password wrong at the admin panel, or turns off remote access to that panel when it isn't in use, the firewall becomes an easier target to grind at than forcing entry through any other path.
In Brazil, the same Sophos survey, in a country-specific breakdown, shows the ransom demand climbing: the median jumped 63% in one year, from $392,500 to $640,000. There's no specific Brazil breakdown of how much of that comes from a poorly managed firewall, but the international pattern gives a clear hint: when the door in is a neglected edge device, the amount demanded tends to go up, not down.
Why Having the Box Turned On Isn't Enough
The common way to handle a firewall is to buy it, install it, and consider the matter closed. The equipment's light is on, traffic runs through it, and that already looks like proof the network is protected. That's the reasoning Sophos's data pulls apart.
In the survey, 61% of victims said their own firewall identified the attack before the ransomware payload was deployed. Another 32% said it only identified the attack afterward — once the damage had already started. And 7% reported the device never identified the attack at all. The gap between those three groups isn't small: when the firewall caught it early, 50% of companies had data encrypted; when it caught it late, that number rises to 65%; when it caught nothing, it reaches 71%.
In other words, a firewall only does its job as a line of defense when someone makes sure it's configured to notice what's off and send that alert to an actual person — not just log it in a report no one opens. A device with an expired content-filtering license, a rule too old to make sense anymore, and no one watching what it flags behaves, in practice, as if it weren't there at all.
The same reflex shows up on the other side, when a company discovers the gap and the fix becomes buying yet another box — another device, another contract — without changing the routine of whoever looks after what's already installed. The new device inherits the same fate as the old one: installed, forgotten, revisited only when it breaks.
What Has to Be in Place
A well-kept firewall runs on routine, not on trust in the box. The mechanisms below are what's usually missing when no one has this equipment as a fixed responsibility.
Periodic review of every open rule. Every rule in place — including the one opened "just for the vendor to test" — has a creation date and a reason. If no one remembers why it exists anymore, it should have been closed long ago.
Firmware always on the vendor's current version. A firewall is software running on a network appliance, and it gets security fixes like any other software. Staying on the install-day version means staying exposed to every flaw discovered since that day.
Content-filtering subscription renewed and tracked. Much of the ability to block a new threat depends on a license that has to be renewed — and that doesn't announce on its own when it lapses. Someone needs to track that date the way they track any other contract.
Alerts reaching a person who looks at them right away, not just a stored report. A sign of an out-of-pattern access attempt, or a repeated password guess, needs to become an alert for someone — cross-checked against what's happening on the rest of the network — not just one more line in a log file.
One single owner for the device. When four different people have touched the configuration over the years and none of them documented what they did, no one can say with confidence what the firewall's current state actually is — only the state each of them remembers.
This is how Skills IT works: with periodic review of firewall rules, firmware kept current, and one owner tracking every change made to it, instead of leaving the device on its install-day settings.
The Payoff for the Business
Keeping the firewall as a routine, not a forgotten box, pays off in two places. The first is a lower chance of it becoming the way in — and, if it does anyway, a better chance it flags the attack early, when the gap between 50% and 71% of data encrypted can still swing in the company's favor.
The second is financial, and it applies to a business of any size: according to the breach impact study that accompanies Verizon's 2026 report, in the most extreme cases — the worst 2.5% — a data breach's damage already consumed more than 7% of the affected company's revenue. For a small or mid-sized business without the cash reserve to absorb a hit that size, that share of revenue is the equivalent of months of payroll.
There's also a less visible payoff: predictability. A company that knows the state of its own firewall can plan the license renewal, the cost of the review, and the equipment replacement ahead of time — instead of discovering all of it in the middle of an investigation, under pressure, with no time to compare price or vendor.
When the firewall identified the attack before the ransomware was deployed, 50% of companies had their data encrypted; when it identified nothing at all, that number reached 71%.
A Starting Checklist
Before assuming the firewall is handled just because it's turned on, these are worth bringing to the next IT meeting:
- Can anyone say, without looking it up, when the firewall rules were last reviewed? If the answer is "it's been a while" or "I don't know," that review is already overdue.
- Is the content-filtering subscription active, with a renewal date tracked somewhere? A license that lapses unnoticed is the same as having no license at all.
- Is the device's firmware on the latest version the vendor recommends? If the answer is "I don't know when it was last updated," that's the next task, not an open question.
- Who receives the firewall's alert when something is out of pattern, and what do they do with it? An alert that only gets logged protects no one.
- Is there a rule that's been open for years, "just for that one test," that no one remembers the reason for? A rule with no owner is the door that stays unlocked by accident.





