The context
The direction of enterprise security spending has reversed. After a decade of adding products, organisations are now consolidating — cutting vendor count, reducing the number of consoles their teams have to reconcile, and pushing more enforcement through fewer points. The driver is rarely cost. It is that estates assembled incident by incident become impossible to operate, and impossible to evidence during an audit.
A financial services group had reached that condition across eleven firewalls spanning head office, two data centres and a disaster recovery site. Every one of them had been correctly specified at the time it was bought. None had been reviewed since.
The rule base told the story. The head office pair carried more than two thousand policies, a significant share permitting traffic to addresses that no longer existed, for applications long decommissioned, under change references nobody could trace. The security team had reached the point where every request was answered by adding a rule, because removing one carried unknown risk and adding one carried none.
That is the mechanism by which a perimeter quietly stops functioning. It still blocks what it was told to block in 2019. It has no coherent position on anything since.
The approach
ITBuilders began with rule base analysis against live traffic over a full business cycle, which is the only reliable way to distinguish a policy that is load-bearing from one that is merely old. Roughly forty percent of the rule set had matched no traffic at all in that period. Another portion matched traffic permitted far more broadly than necessary — entire subnets allowed where a single host was in use.
Consolidation was designed rather than executed rule by rule. A policy model was built around application, identity and data sensitivity, so that a rule expresses a business permission rather than an address pairing. Rules written this way survive a server migration, an addressing change and a cloud move, which is precisely why the original estate had degraded.
Inspection was the second gap. Encrypted traffic made up the large majority of the outbound flow and was passing uninspected, a decision made years earlier on performance grounds and never revisited. Reintroducing inspection required capacity planning against actual throughput, a defined exclusion list for traffic that cannot be inspected for legal or technical reasons, and certificate distribution handled properly across managed devices.
Segmentation followed. The group's internal network had been flat behind the perimeter, meaning a compromised workstation had a clear path to the core banking environment. Internal enforcement points were introduced between zones, built to the same policy model, so that lateral movement now crosses a boundary that inspects it.
High availability was rebuilt and, more importantly, tested. The existing pair ran an active-passive configuration that had never been failed over in production. It did not work. Discovering that during a planned test cost an evening.
Cutover ran in monitored stages, with new policy logging before enforcing, so that anything the analysis had missed surfaced as a log entry rather than a business outage.
ITBuilders holds the Fortinet Engage Partner Specialization in Secure Networking Firewall. Consolidation work carries more risk than deployment work — the failure mode is an outage in a production environment during a change the business did not ask for. The credential is Fortinet's own assessment of capability, which is the only independent signal available to a buyer weighing that risk.
What changed
The group now runs a few hundred policies, each with a documented owner and business justification, under a quarterly review cycle. Change requests are answered in hours rather than days because the model is legible. Encrypted traffic is inspected. The perimeter has a current position on current traffic.
Continuity of operation
ITBuilders continues to operate the review cycle, manage change execution against the policy model, and maintain the documentation the group's auditors rely on. A rule base decays from the day it is rationalised, and the only thing that prevents a return to two thousand policies is a maintained process with an owner.



