Here’s a statistic that should change how you think about network security. Gartner found that 99% of firewall breaches are caused by misconfiguration — not by flaws in the firewall itself.
The product almost never fails. The setup does. Capital One learned this the hard way in 2019: a single firewall misconfiguration exposed the personal data of more than 100 million people. The firewall worked exactly as configured. The configuration was the breach.
For business leaders, this flips the usual security question. “Do we have a firewall?” is the wrong thing to ask. Everyone has one. The real question is whether yours still matches how your business actually operates — and whether anyone is checking.
The Myth That Creates the Gap
Many leaders assume that moving to the cloud means Microsoft handles security. That assumption has a body count. Gartner projects that through 2026, 99% of cloud security failures will be the customer’s fault, mostly through misconfiguration.
Cloud security runs on a shared responsibility model. Microsoft secures the infrastructure — the data centers, the hardware, the platform. You secure everything you build on top of it: your data, your access rules, your configurations. Azure Firewall is a strong tool. Microsoft keeps expanding it, with 2026 updates focused on policy management, deeper traffic inspection, and tighter integration across its security products. But Microsoft ships the tool. Your team, or your IT partner, decides what it allows through. That decision layer is where breaches happen.
How a Firewall Quietly Rots
No one breaks a firewall on purpose. It drifts, one reasonable decision at a time:
- A vendor needs access for a project, so someone opens a port. The project ends. The port stays open.
- An app won’t connect, so someone creates an exception “for now.” Now is three years ago.
- An employee leaves, but the rules built around their tools remain active.
- The company adds cloud apps, remote workers, and new locations. The firewall rules still describe the office of 2022.
Each change made sense on the day it was made. Nobody wrote down why. Nobody was assigned to review it. Multiply that by years and you get what most businesses actually have: a firewall full of doors nobody remembers opening, protecting a company that no longer exists in that shape.
This applies on every level — the Azure Firewall guarding your cloud resources and the Windows Firewall built into every company laptop. Microsoft’s own guidance is telling: keep default protections on, and when an app needs access, allow that specific app rather than opening a port. An open port is a hallway anyone can walk down. An app exception is a door with a name on it.
The Zero Trust Connection
You may have heard “Zero Trust” pitched as the modern replacement for firewalls. It isn’t a replacement — it’s a philosophy your firewall enforces. Zero Trust means no connection gets a pass just because it comes from inside your network. Every user, device, and app should only reach what its job requires.
Your firewall rules are where that principle becomes real. Loose rules mean that once an attacker gets in anywhere, they can move everywhere. Tight rules turn one compromised laptop into a contained problem instead of a company-wide one.
Five Questions That Reveal Your Exposure
You don’t need to read a single firewall rule to find out where you stand. Ask whoever manages your IT:
- Which applications and ports are allowed through our firewalls right now?
- Why does each exception exist — and is that reason still true?
- When did we last remove old or unused rules?
- Who owns firewall reviews, and how often do they happen?
- Do our cloud and device firewall settings match how the business runs today — or how it ran when they were set up?
Strong answers come back specific and fast. Vague answers — “we’d have to check” — tell you the rules haven’t been reviewed in years. That’s not an insult to your IT people. Rule reviews are exactly the kind of important-but-never-urgent work that loses to daily fires in every busy business.
Where Crimson IT Fits
Crimson IT treats firewall management as ongoing discipline, not a set-it-and-forget-it install:
- A full rule review across Azure and Windows environments that finds the open ports and forgotten exceptions before an attacker does
- Documentation for every exception — what it allows, why it exists, and when it gets reviewed again
- Configurations that match your Zero Trust and insurance requirements, so your security story holds up to an auditor or a carrier
- Scheduled reviews built into your service, because a firewall is only as good as its last checkup
The firewall you bought was fine. The question is what three years of quick fixes have done to it since.
Want to know how many forgotten doors your firewall is holding open? Ask us for a network security review — we’ll show you the list before anyone else finds it.






