About FwChange

Built on field-tested methodology

FwChange is not a product written by people who read about firewalls. It was built from the field, after watching the same migrations fail the same preventable way. The software encodes a method already proven by hand.

FW
FwChange
Firewall change management methodology
Hundreds of firewall migrations 33+ vendors supported Regulated & enterprise estates

The background

Built inside the change window

The method comes from hands-on work in the field: migrating firewall estates, rationalizing rule bases, and standing in front of auditors who want to know who changed what, when, and why.

The method draws on a dataset of hundreds of firewall migration projects spanning regulated and enterprise environments. Names stay anonymized; the patterns do not. The same preventable failures repeat at every scale: shadow rules nobody finds, manual translation errors between vendor syntaxes, and compliance evidence reconstructed under deadline because no system captured it as the change happened.

FwChange exists because those problems were being solved by hand, over and over. It encodes field-tested method into software, so the analysis that used to live in an engineer's head is now a step in the workflow.

Field-tested methodField
Hundreds of firewall migrationsDelivered
Regulated & enterprise environmentsCoverage
KRITIS / regulated infrastructureSpecialism
Built FwChange from the methodOutcome

What FwChange covers

Built for regulated and enterprise environments

FwChange is built for the environments where a wrong firewall rule is both a security incident and an audit finding. These are the frameworks and estates the platform is designed around.

Critical infrastructure (KRITIS) NIS2 DORA PCI-DSS ISO 27001 TISAX BSI IT-Grundschutz Zero Trust segmentation OT/IT convergence Multi-vendor estates

Specialization

Where the method goes deep

The work sits where regulated infrastructure meets multi-vendor firewall estates, the place where a wrong rule is both a security incident and an audit finding.

  • KRITIS & regulated infrastructure, firewall policy and segmentation for BSI-regulated operators.
  • PCI-DSS firewall rationalization and audit-trail documentation for payment environments.
  • BSI IT-Grundschutz aligned controls for German regulated enterprise.
  • Zero Trust, micro-segmentation that scales change management instead of breaking it.
  • OT/IT convergence, segmentation where the network spans both worlds.
  • Multi-vendor migration, cross-syntax translation without losing intent.
KRITIS segmentationDeep
PCI-DSS firewall scopeDeep
BSI IT-GrundschutzDeep
Zero Trust micro-segActive
OT/IT convergenceActive
Multi-vendor migrationCore

FwChange was born from one observation repeated across hundreds of projects: enterprise firewall migrations fail the same preventable way: undetected shadow rules, manual translation errors between vendor syntaxes, and compliance evidence that has to be reconstructed after the fact. The platform turns each of those into a step the software handles, not a thing a senior engineer has to remember.

See the method, not the pitch

The platform is the proof. The methodology page walks the thinking behind every part of it, the same reasoning proven in the field before any of it was code.