Our position

The cheapest firewall is often the most expensive decision

You buy a device once. You have to run it every day. That second part is rarely in the quote, and it is the part that decides whether the hardware protects anything or merely looks like it does.

Our position

A security device is worth exactly as much as its upkeep, so judging a quote by the purchase price alone does not save money — it postpones it.

Why is the cheapest firewall quote not automatically the cheapest option?

Because the purchase price is only the opening line of the bill. A security device becomes what you bought it for through setup, well-kept rules and regular updates, and that work exists regardless of what the box cost. There is also a question that never sits at the top of a datasheet: how long the vendor will keep shipping security updates for that exact model. At NDVDL we therefore put the support period and the ongoing maintenance into the quote itself, even though this makes us look expensive next to a bare hardware price. A device that still runs but no longer gets updated looks identical in the rack to one that is safe, and that resemblance is the actual problem.

01

The purchase price is the smaller part

Between a device in a box and a firewall that genuinely separates things lies work: understanding which systems have to talk to each other and which must not, building rules cleanly, documenting the exceptions, securing remote access, and doing all of it without stopping the business. That effort depends on your network, not on the model number. It does not shrink because the hardware was cheaper.

So the acquisition price says very little about total cost. When a quote lists hardware and leaves configuration open, the difference has not disappeared — it has simply not been priced yet. It shows up later, usually at an inconvenient moment, and usually as hours.

02

A device without update supply is not a security device

Security hardware lives on updates. Attack paths change, weaknesses become public, and the answer arrives from the vendor as firmware and signatures. When that supply ends, the protective effect ends with it — not abruptly, but steadily. Meanwhile the device keeps running and behaves outwardly exactly as before.

How long a model will be supported is known at purchase time, or can at least be asked. In our view it belongs in the decision the same way spare-part availability belongs in the decision to buy a machine. A device near the end of its support period can be a good deal today and an unplanned replacement project not long after.

03

Neglect ages quietly

An unmaintained firewall does not complain. It does not fail, no light turns red, and nobody notices anything in daily work. That is what makes it more dangerous than having no device at all: it creates the certainty of being protected, so nobody asks the question a second time. Rules opened years ago for one specific purpose stay open long after the purpose is gone.

Maintenance, for us, does not mean constantly rebuilding things. It means looking regularly, applying updates, cleaning up rules, and reviewing accesses left over from old projects. It is unglamorous work, and it is why a simple, well-kept device is almost always worth more than a powerful one nobody touches anymore.

What speaks for the opposite view

Budgets are real and limited, and that is not a mistake in reasoning — it is the situation many companies are in. A simple device whose purchase and whose ongoing upkeep a business can carry for years protects better than a stronger one that runs out of maintenance budget later, because then it is precisely the expensive box that sits neglected in the cabinet. A company that keeps the scope small in order to keep the upkeep affordable is often making the more sensible call, not the weaker one. And there are networks modest enough that an elaborate device ties up money which would do more elsewhere: in backups, in separating the network, or in how staff accounts and remote access are handled.

What this means for working with us

  • We put setup, ongoing maintenance and the device's support period visibly into the quote, even though that makes our number look larger beside a bare hardware price.
  • We would rather recommend the simpler device whose upkeep you can carry for years than the larger one with features that will have nobody looking after them.
  • When you are comparing several quotes, we tell you which points every one of them should contain, even when the answers end up counting against us.

Does that sound like your situation?

Then let us talk about what it concretely means for your business.

IT security & firewall
Follow-ups

What we get asked about this

By whether three things are named: who does the setup and to what extent, who applies updates and how often, and how long the vendor will still supply security updates for the model being offered. If one of them is missing, it has not gone away — it has only gone unpriced.

At first, nothing visible. The device keeps working as before. But newly discovered weaknesses are no longer closed, and the gap between what the device can fend off and what is actually attempted widens over time. That is why we treat the end of the support period as a date to know and plan for.

Often not. For small, manageable networks we more frequently suggest the simpler device plus careful setup and reliable upkeep. In that kind of environment, the difference between maintained and neglected matters more than the difference between two performance classes.

Frequently yes. We first look at what is there, what condition the configuration is in, and how long the devices will still be supported. If cleaning up, updating and separating the network properly achieves more than a replacement, we say so, even when that means no hardware is sold.

Before you commit to a device

We will walk through what a quote for security hardware should contain and what your network actually needs. No sales pressure, by phone or on site.