The Router From the Telco Wasn't Enough: A Hong Kong Manufacturer's Managed Firewall Upgrade
A composite scenario from Hong Kong: a light-manufacturing SME had run for years on the router its telco bundled in with the internet line, until a routine security review found no real firewall policy at all — just factory defaults on a network that had grown to include production-floor equipment alongside office PCs. Why a managed, SME-scale next-gen firewall — not an enterprise offering, and not the telco's bundled router — closed that gap, and what it looks like bundled into a managed IT plan.
Published
In short: A Hong Kong light-manufacturing SME had run for years on the router its telco bundled in with the internet line. A routine security review found no real firewall policy at all — just factory defaults nobody had ever touched, on a network that had quietly grown to include production-floor devices alongside office PCs. Upgrading to a managed next-gen firewall, priced and scoped for an SME rather than an enterprise, is what closed that gap.
A Network That Outgrew the Router Nobody Thought About
Most Hong Kong light-manufacturing SMEs — the kind running a 50-to-90-person operation out of an industrial building in Kwun Tong, Kwai Chung, or across the border in a satellite facility — didn't set out to build a complicated network. It grew the way these things grow. A handful of office PCs for admin, sales, and finance. Then a few networked label printers on the production floor. Then a barcode scanner system tied to inventory. Then a couple of IP cameras over the loading bay. Then a CNC controller or a PLC that someone on the floor insisted needed "just a quick internet connection for firmware updates." None of it happened as a project. It happened as a series of small, reasonable-sounding requests, each one plugged into whatever network hardware was already there.
And in a lot of these companies, what was "already there" is the router the telco handed over when the internet line was installed. It routes traffic. It has a login screen with a factory-default password half the office still doesn't know exists. It has never been opened, audited, or reconfigured since the day the installer left. Nobody thought of it as a decision — it was just the box that came with the internet.
That's the starting point for a huge share of Hong Kong's SME manufacturers, and it's worth being specific about why this particular industry and this particular size band is the one where it matters most. Manufacturing networks are different from a pure office network in one important way: they mix two classes of device with very different security postures on the same physical network. Office PCs get patched, get antivirus, get replaced every few years. Production-floor equipment — PLCs, CNC controllers, older Windows-based machine interfaces, barcode and label print servers — often runs for a decade or more on firmware nobody updates, because updating it risks downtime on a line that can't afford to stop. That equipment was never designed with the assumption that it would ever be exposed, even indirectly, to the open internet. When office and floor sit on the same flat network behind a bundled telco router, that assumption gets violated quietly, and nobody notices until something forces the question.
For a lot of these companies, the thing that forces the question is not an incident. It's a client. Hong Kong manufacturers doing contract work for overseas brands — especially anyone selling into the EU, the US, or into supply chains with their own vendor-security requirements — increasingly get a security questionnaire attached to a renewal or a new contract. Or a cyber insurance renewal comes up and the broker asks what's actually managing the network perimeter. Or a new IT lead does a walkthrough in their first month and asks the question nobody else had thought to ask: what is our actual firewall policy? The honest answer, for a router that came free with the internet line, is usually: there isn't one.
What "We've Never Had a Problem" Actually Looks Like
The scenario that plays out at this scale is remarkably consistent. A Hong Kong manufacturer — say, 60 to 80 staff, split between an office area and a production floor in the same industrial building — has been running the same bundled router since the internet line went in, however many years ago that was. Nobody remembers exactly. The router works. Pages load. Orders get placed and shipped. By every measure anyone in the building actually checks day to day, everything is fine.
What that everyday view doesn't show is what's underneath it. There is no segmentation between the office network and the production floor — a laptop in the sales office and a PLC controlling a stamping machine are, from a network perspective, neighbors on the same subnet. There is no visibility into what's actually crossing the perimeter: no logging worth looking at, no alerting, nothing that would tell anyone if a piece of floor equipment started talking to an address it has no business talking to. There is no one — not IT, not the outsourced vendor, not anyone — who has ever actually logged into the router's admin panel and reviewed what rules, if any, are configured. In more cases than most owners would guess, the honest answer is "factory defaults," full stop.
And there's a specific misunderstanding that keeps this arrangement in place longer than it should: the assumption that because the telco calls its offering "managed," the security is handled. It isn't, and it was never meant to be. A telco's "managed" service, in the router-bundled-with-the-line sense, means the telco keeps the connection itself running — the physical line, the modem, basic connectivity troubleshooting. It does not mean anyone at the telco is reviewing, tuning, or even looking at the firewall policy running on that router, because in most bundled setups there functionally isn't one to review. The telco's job stops at the handoff point where the internet becomes the customer's problem. Nobody on either side of that handoff is actually managing the security policy on top of the connection — and that gap is exactly where this whole scenario lives.
What No One Configuring a Firewall for Years Actually Costs a Manufacturer
None of this shows up as a line-item cost, which is precisely why it persists. But it produces three concrete, specific exposures that are worth naming plainly, because "we've never had a problem" is not the same as "we have no exposure."
No traffic visibility. Without a real firewall policy and real logging, nobody in the business can answer a simple question after the fact: what actually happened on our network last week? If a piece of equipment on the floor starts behaving strangely, or a laptop starts sending unusual amounts of data out, there's no record to look at and no alert that would have caught it in the moment. The first sign of a problem, in this setup, tends to be the problem itself — a machine down, data missing, a client asking uncomfortable questions — not a warning that arrived earlier.
No segmentation between office and floor. This is the sharpest exposure for a manufacturer specifically, because it means the office — the part of the network most exposed to email attachments, personal browsing, USB drives, and general human error — sits on the same flat network as production equipment that, once compromised or disrupted, can actually stop the line. A phishing email opened on an office PC is a bad afternoon in most businesses. On a flat network with no segmentation, it's a bad afternoon that can propagate straight to whatever is running the stamping press or the packing line.
A "managed" service that stops at the wire. This is less a technical gap than an organizational one, but it's arguably the most persistent, because it's the reason the first two exposures don't get fixed even after someone notices them. When the telco's "managed" language creates the impression that security is covered, nobody owns the follow-up. IT (if there is a dedicated IT person at all, which at this size band is often not the case) assumes the telco has it. The telco's scope never included it. The outsourced IT vendor, if there is one, may not have been explicitly asked to look at the firewall specifically, and firewall policy review isn't something most generalist support arrangements do unless it's named. The result is a gap nobody is actively covering, sitting underneath everyone's honest but mistaken assumption that somebody else is.
A Firewall Is a Policy, Not a Box
This is the point where it's worth being direct about how we think about this problem, because the framing matters more than the hardware. A firewall is not something a business "has" the way it has a router or a switch. A physical firewall appliance sitting in a rack is inert — it enforces exactly the policy someone configured on it, and nothing more, and that policy needs to keep changing as the business does. New vendor added, new remote-access need, new piece of production equipment, new employee laptop, new client requiring a specific compliance answer — every one of those is a reason the policy on day one is wrong by month six if nobody is actively maintaining it. A basic router treated as a firewall isn't a weaker version of a real firewall policy. It's the absence of one, wearing the shape of a network device.
That's the actual meaning behind "managed premium firewall" as we scope it for a client, and it's worth being specific rather than using the word "managed" the same loose way the telco does. It means a next-generation firewall appliance, sized to the business rather than to an enterprise data center, running an actively maintained policy: someone reviewing and updating firewall rules as the business changes, not a policy set once at install and never revisited. It means segmentation designed in from the start — office traffic and production-floor traffic separated into distinct network zones with rules controlling exactly what, if anything, is allowed to cross between them. It means real logging and alerting, so that unusual traffic produces a signal someone actually sees, rather than a record nobody ever queries. And it means it's genuinely someone's job to own that policy, on an ongoing basis, rather than a responsibility that quietly falls into the gap between "the telco's problem" and "the office's problem" and ends up belonging to neither.
The scale point matters as much as the technical one. Hong Kong's managed firewall market, as most SME owners encounter it, is dominated by offerings built and priced for large enterprises — telco-and-Fortinet partnerships and integrators sized for corporates with dedicated security budgets and IT headcount most manufacturers this size don't have and don't need. That's not a criticism of those offerings; they're built for a different buyer. But it leaves a real gap for the SME/mid-market scale — a 60-to-90-person manufacturer that has genuine exposure (office-floor mixing, client security questionnaires, cyber insurance renewals) but doesn't need, and shouldn't have to pay for, an enterprise-grade security operation sized for a company ten times its size. That SME-scale gap — priced and scoped correctly for a smaller network, not a scaled-down enterprise offering — is specifically what this kind of upgrade is built to close.
What Changes When the Firewall Becomes a Managed Service
In practice, closing that gap looks less like a single hardware swap and more like establishing an ongoing relationship between the network and the people responsible for its policy. The physical piece is straightforward: a next-generation firewall appliance, sized to the site's actual throughput and device count rather than an enterprise's, replaces the telco's bundled router at the network edge (or sits behind it, depending on the existing setup). The more important piece is everything that happens after the box is installed.
Segmentation gets designed around how the business actually operates, not a generic template — office network, production-floor network, and often a separate zone for guest or vendor access, with explicit rules governing what can and can't cross between them. A compromised office laptop, in a segmented network, is contained to the office zone; it can't reach the stamping press or the PLC controlling the packing line, because the rule set doesn't allow it to. Policy review becomes a recurring activity rather than a one-time install step — new vendors, new remote-access requirements, new equipment on the floor all get reflected in the ruleset as they happen, not discovered as a gap during the next audit or the next security questionnaire. Logging and alerting turn "we've never had a problem" from an assumption into something that can actually be verified, because there's now a record to check and a signal that fires when something looks wrong.
And critically, none of this requires the manufacturer to build or hire for a security function of its own. This is the specific difference between the enterprise-managed-firewall category and the SME-scale version of it: firewall coverage becomes a component that's bundled into a managed IT plan rather than a separate specialty product bought and configured in isolation from a telco add-on. On our own plan structure, managed firewall sits alongside the other things a manufacturer at this size needs handled day to day — help desk, patch management, backup, endpoint protection — as one included, actively maintained piece of the same relationship, not a standalone purchase decision requiring its own vendor, its own contract, and its own review cycle. For a 60-to-90-person manufacturer without a dedicated security function, that's the difference between a real security policy and a router nobody has opened since installation.
Telco Router vs. Enterprise Managed Firewall vs. SME-Scale Managed Firewall
- Telco-Provided Basic Router — Provides connectivity, nothing more. No real security policy, no segmentation, no logging worth reviewing, factory-default configuration in most installs. "Managed" refers to the connection, not the security running on top of it.
- Enterprise Managed Firewall — Thorough, well-resourced, and genuinely capable — but priced, scoped, and staffed for corporates with dedicated security budgets and IT headcount. Built for a scale most 50-to-90-person manufacturers don't have and don't need to match.
- SME-Scale Managed Firewall (Brocent's model) — A next-generation firewall sized to the actual business, with office/floor segmentation, an actively maintained policy, and real logging — priced and scoped for a smaller network, and bundled into a managed IT plan rather than sold as an isolated specialty product.
Frequently Asked Questions
Isn't the router from our telco already a firewall?
Most bundled telco routers have basic firewall functionality baked in — but "having the capability" and "running an actively maintained policy" are different things. In most bundled installs, nobody has ever logged in to configure rules, review logs, or set up segmentation, which means the router is technically capable of enforcing a policy while actually enforcing none. The telco's "managed" language covers the connection itself, not the security configuration running on top of it.
What does "managed" firewall actually mean, day to day?
It means someone is actively responsible for the policy running on the firewall, on an ongoing basis — reviewing and updating rules as the business changes (new vendor, new remote-access need, new equipment), monitoring logs and alerts for unusual traffic, and handling policy changes when something urgent comes up. It's the difference between a device that's technically present and a security control that's actually being operated.
Can this actually segment our office network from the production floor?
Yes — that's one of the core changes a proper firewall policy makes possible. Office traffic and production-floor traffic get separated into distinct network zones, with explicit rules controlling what, if anything, is allowed to cross between them. A compromised office device stays contained to the office zone rather than having an open path to equipment running the production line.
Is managed firewall included in a managed IT plan, or is it a separate purchase?
Managed firewall is one of the items included across our managed IT plan tiers, alongside things like help desk, patch management, and backup — it's not sold as a standalone add-on that requires its own separate contract. That's a deliberate structural difference from the telco/integrator model, where the connection and the security policy on top of it are two unrelated things nobody is responsible for connecting.
How is managed firewall priced for an SME manufacturer at this size?
Pricing depends on the site's device count, throughput needs, and whether segmentation spans multiple physical locations. Rather than publish a single figure that won't reflect an actual site's setup, current firewall and network security pricing is maintained on our pricing pages, and a specific quote for a given site takes a short conversation about the network's actual layout.
What happens if the firewall policy needs an urgent change — a new vendor, a security incident, an audit finding?
Because policy review is an ongoing part of the managed service rather than a one-time install step, urgent changes get handled as part of that same relationship — there's no separate vendor to call, no new contract to negotiate, and no delay while someone tries to figure out who's actually responsible for the box.
Does upgrading to a managed firewall replace our existing internet connection?
No — the internet line and the telco relationship for connectivity stay exactly as they are. A managed firewall replaces (or sits behind) the router handling security policy at the network edge; it doesn't touch the underlying connection itself. The two are genuinely separate things, which is part of why it's worth being clear-eyed about what the telco's "managed" language does and doesn't cover.
Where Firewall Coverage Fits Inside a Managed IT Plan
The mistake worth avoiding here isn't just running on an unconfigured router — it's treating "managed firewall" as one more specialty product to shop for in isolation, the way the enterprise-managed-firewall category is typically sold. For a manufacturer at this size, the more useful question isn't "which vendor sells the best standalone firewall service," but "who is actually responsible for this, alongside everything else that keeps the network running."
That's the frame we'd encourage any Hong Kong SME manufacturer in this position to start from. A managed premium firewall, sized and segmented for the business rather than for an enterprise, comes bundled into our managed IT plan as one of the included components — not a separate telco add-on with its own contract and its own gap in ownership. If your team wants to see current Fortinet appliance options and how they're scoped for a site your size, our Fortinet pricing page and network security pricing page lay out what's on offer today. But the more useful starting point, if the real question is "who is watching our firewall policy and everything else that comes with running this network," is our pricing page for the plan itself, or a direct conversation through contact us about what a segmented, actively managed setup looks like for a site your size.
Share:
Ready to take action?
Turn these insights into a roadmap for your business.
Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.
Free Checklist
10 Critical Checks Before Expanding IT to Greater China
PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.
Request the checklist →📬 Monthly Asia IT Insights
China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.
No spam. Unsubscribe anytime.