Product Story

Why FwChange Exists

firewall change management toolwhy FwChange existsmid-market compliance
A messy firewall spreadsheet transformed into a clean purpose-built tool

In enterprise security practice, the same problem keeps surfacing. Companies spend millions on firewalls but can’t answer basic audit questions: Who requested this rule? Why does it exist? Who approved it?

Firewall audits across Germany and Europe tell the same story. TISAX assessments, PCI-DSS audits, ISO 27001 certifications: the technology was always fine. The documentation was always a disaster.

That’s why FwChange exists — a purpose-built firewall change management tool. Not because the world needed another security product, but because the existing solutions didn’t solve the actual problem mid-market companies face.

The Recurring Problem

Every audit starts the same way. Ask to see firewall change records, and the IT team produces a mix of:

  • Excel spreadsheets with missing entries
  • JIRA tickets that didn’t link to actual rules
  • Email threads nobody could find
  • Tribal knowledge from engineers who’d since left

The firewall itself worked perfectly. Palo Alto, Check Point, Fortinet, all properly configured, all protecting the network. But when auditors asked “show me the change history for this rule,” everything fell apart.

Companies fail audits not because their security is weak, but because they can’t prove their security is strong. Documentation gaps turn passing grades into major findings.

The BSI doesn’t accept “we think someone approved this in 2019” as evidence. Neither does any serious auditor.

Why Existing Tools Don’t Work for Mid-Market

Enterprise firewall change management tool options exist. AlgoSec, Tufin, FireMon, they’re excellent products, widely deployed across large enterprises. But they share common problems for mid-market companies:

Cost

Enterprise licensing starts at €100,000+ per year. For a company with 5-10 firewalls, the math doesn’t work. You’re paying for capabilities you’ll never use.

Complexity

These tools require dedicated administrators. Multi-month implementation projects. Professional services engagements. Mid-market IT teams don’t have those resources.

Overhead

The workflow overhead often exceeds the benefit. Engineers resist tools that triple the time to make a simple change. Adoption fails, and you’re back to spreadsheets.

One 200-person manufacturer spent €150,000 on an enterprise solution, struggled through 6 months of implementation, and still failed its TISAX audit because nobody actually used it. The tool sat there while changes happened via SSH and manual documentation.

The Breaking Point

Consider a representative case: a TISAX assessment at a Tier-1 automotive supplier with a good security team, modern infrastructure, and real commitment to compliance. They’ve done everything right except document their firewall changes.

The auditor asks for 6 months of change history. The IT manager produces a spreadsheet with 40 entries. The firewall logs show 200+ changes in that period. The gap is inexplicable.

Emergency changes. After-hours modifications. Rules added during incidents. All undocumented because the process was too cumbersome to follow under pressure.

The audit fails. Not because the firewall is insecure, it is excellent. It fails because the team cannot prove governance over its change management process, and a major customer contract can hang in the balance while they scramble to remediate.

This pattern repeats too often. Talented teams, solid security, failed audits. The tools weren’t the problem. The process was the problem. And the existing solutions made the process worse, not better.

What FwChange Does Differently

FwChange is built around one principle: documentation should happen automatically, not as extra work. When you make a change through FwChange, documentation is the byproduct. You’re not filling out forms after the fact. You’re making the change, and the audit trail generates itself.

Request

Someone needs a firewall rule. They submit through FwChange with business justification. Takes 2 minutes.

Approve

Approval workflow routes to the right people based on priority. They approve in Slack, Teams, or the web UI. One click.

Implement

The change pushes to the firewall automatically. Or an engineer implements manually and marks complete. Either way, it’s tracked.

Document

Every step is logged automatically. Who requested, who approved, who implemented, when, why. Immutable record.

When auditors ask for change history, you generate a report. Everything’s there. No spreadsheet archaeology required.

Designed for Real IT Teams

A firewall change management tool only works if people use it. FwChange is designed for the mid-market IT teams these audits kept encountering:

  • Fast deployment: Docker containers, 2-hour setup. No professional services required. Your team can do it.
  • Multi-vendor: Palo Alto, Check Point, Fortinet, Cisco, OPNsense, pfSense. One interface for all your firewalls. According to industry research, most mid-market companies run 2-3 firewall vendors.
  • Low friction: Changes take minutes, not hours. Engineers adopt it because it’s faster than the old way, not slower.
  • Affordable: Per-firewall pricing that makes sense for mid-market budgets. Not enterprise pricing for mid-market needs.
  • JIRA/Taiga integration: Link to existing tickets. Don’t force a separate workflow. Meet teams where they already work.

The goal was simple: make the right thing to do also the easy thing to do. If documentation requires extra effort, it won’t happen. If documentation is automatic, it always happens.

Solving Real Audit Problems

Every feature in FwChange traces back to a real audit problem:

  • Rule ownership:“Who owns this rule?” Every rule has an assigned owner. No more orphan rules that nobody claims.
  • Business justification: “Why does this rule exist?” Required field on every request. Not optional, not “we’ll add it later.”
  • Approval evidence: “Who approved this?” Timestamped approval records with the approver’s identity. No ambiguity.
  • Rule review:“When was this last validated?” Scheduled review reminders. Annual recertification tracking. Evidence of ongoing governance.
  • Emergency changes: “What about urgent changes?” Emergency workflow with expedited approval and retroactive documentation. Because emergencies happen.

The ENISA guidelines on network security management informed much of this design. The goal was a firewall change management tool that auditors would value as much as IT teams.

What Building the Product Demanded

Building a product is different from consulting. Consulting identifies problems and recommends solutions; a product has to solve them completely. That difference surfaces lessons an advisory engagement never forces:

  • Simplicity is hard: Anyone can build a complex tool. Building something simple that solves the problem, that’s the challenge. Every feature request gets evaluated: does this make the core workflow better or worse?
  • Users vote with behavior: In consulting, you deliver recommendations and move on. In product, you see whether people actually use what you built. That feedback loop is humbling and invaluable.
  • Support is product: When a customer struggles, that’s not a support ticket, it’s a design flaw. If the tool needs explanation, the tool needs improvement.

The methodology behind FwChange still informs audits and assessments. What changed is that the same problems those engagements kept documenting now have a solution built specifically for them.

What’s Next

NIS2 takes effect in 2026. TISAX requirements keep tightening. The demand for firewall change management solutions will only grow as mid-market companies face compliance requirements previously reserved for enterprises.

FwChange is ready. Built from the auditor’s side of the table, it knows exactly what evidence auditors need. Built for IT teams who need solutions that work, not products that promise.

If you’re facing TISAX, NIS2, PCI-DSS, or ISO 27001 compliance, and your firewall documentation is held together with spreadsheets and hope, FwChange was built for you. Try the free rulebase scanner and see why documentation should be automatic, not additional work.

FW

FwChange

Firewall change management

Methodology and software for firewall change management, drawn from a large dataset of enterprise firewall migrations.