Author: Ami DePierro | Co-Founder, 2 Dog Digital
Ami DePierro is Co-Founder of 2 Dog Digital and a former US Marine Intelligence Analyst who brings analytical precision to cybersecurity strategy for small and mid-sized businesses across the Raleigh/Triangle area. Digit is the voice. Ami is the author.
What Actually Happened
They usually say it like the conversation is over.
It isn’t.
A firewall is one of the most important pieces of equipment on your network. It stands watch, checks traffic coming and going, and turns away a lot of trouble before it ever reaches your business. But it has limits, and those limits matter.
A law firm here in Raleigh learned that the hard way a couple of years ago. They weren’t taken down by some nation-state or a brand-new zero-day exploit. Someone used stolen usernames and passwords to get into a remote login portal that should have been protected with multi-factor authentication. It wasn’t. Three days of billable work disappeared while they cleaned up the mess, client files were exposed, and the firewall never raised an alarm.
It wasn’t broken.
It was doing exactly what it was designed to do.
Digit’s Rule #5: Multi-factor authentication isn’t optional. Neither is locking the front door.
That’s the part people miss. A firewall isn’t a force field. It’s more like the Marine standing duty at the gate. If someone walks up with valid credentials, they’re getting through. The guard doesn’t know whether those credentials belong to the right person.
Dottie says I’m making this more complicated than it needs to be. She might be right. So let’s keep it simple. Here’s what a firewall actually does, what it doesn’t do, and why understanding the difference is one of the easiest ways to make better security decisions.
What a Small Business Firewall Is Built to Do
Every piece of network traffic, called a packet, goes through that process. The firewall isn’t deciding whether someone has good intentions. It’s simply enforcing the rules it was given.
For a small business, that means a properly configured firewall can
- Block known malicious IP addresses and network traffic.
- Prevent unauthorized connections from reaching your servers.
- Limit access to sensitive internal systems.
- Enforce network segmentation between devices.
- Give your IT team the visibility they need when something doesn’t look right.
According to the 2024 Verizon Data Breach Investigations Report, 68% of breaches involved a human element. A firewall can inspect network traffic. It can’t decide whether someone should click a phishing email or reuse the same password everywhere.
Digit’s Rule #1: If nobody can explain how it was set up, nobody gets to call it secure.
One mistake I see all the time is businesses installing a firewall, leaving the factory defaults in place, and assuming the job is done. Factory defaults are designed to work for almost everyone, which means they aren’t optimized for anyone. Your business changes over time, and your firewall should change with it.
What a Firewall Will Not Protect You From
This is the part that usually gets skipped. Pay attention.
A firewall protects the network. It doesn’t protect every decision people make once they’re on it.
For example, most small business firewalls don’t inspect encrypted HTTPS traffic unless SSL inspection has been configured. To the firewall, a phishing website using HTTPS looks just like your bank’s website. It sees an encrypted connection on port 443 and allows it because, at the network level, everything appears legitimate.
The same thing happens when someone clicks a malicious link in an email. The email arrived through an approved mail service, the computer making the request is already trusted, and the firewall sees a legitimate device connecting to a legitimate website. It has no way of knowing the person on the keyboard was tricked.
A firewall also won’t stop malware that arrives on a USB drive, a compromised software update, or someone’s personal laptop. If it enters through an approved path, the firewall doesn’t have a reason to block it.
And perhaps the hardest lesson for business owners: a firewall can’t stop an authorized user from doing authorized things.
If an employee with legitimate access copies customer data before leaving the company, the firewall sees normal traffic generated by a legitimate account. From its perspective, nothing unusual happened.
That’s why security has to be built in layers. A firewall protects the perimeter. It was never designed to protect against every threat inside the fence.
Firewall Protection: What It Does vs. What It Does Not
| What a Firewall DOES | What a Firewall DOES NOT Do |
|---|---|
| Blocks known malicious IP addresses and ports | Stop phishing emails that trick users into clicking |
| Filters inbound and outbound network traffic | Inspect encrypted HTTPS traffic without SSL inspection |
| Restricts unauthorized access to internal systems | Catch malware arriving via USB or personal devices |
| Logs traffic for your IT team to review | Prevent insider threats from an authorized user |
| Enforces network segmentation rules | Replace endpoint protection or email filtering |
| Reduces your attack surface at the perimeter | Compensate for weak passwords or missing MFA |
Is the Windows Firewall Enough for a Small Business?
…Actually, you came here for the long answer.
Windows Firewall is a host-based firewall built into Windows. It protects the individual computer it’s running on, and you should leave it enabled. Turning it off removes a layer of protection that costs you exactly zero dollars.
What it doesn’t do is protect your entire network.
A business firewall sits at your internet gateway, where it can see traffic moving to and from every device on your network. It gives your IT team centralized visibility, logging, and security controls that Windows Firewall simply wasn’t designed to provide.
Think of Windows Firewall as locking your office door. That’s a good habit. A network firewall locks the front entrance to the building.
Digit’s Rule #6: Your IT team can’t protect a door you didn’t tell them existed.
Running Windows Firewall on each machine and calling it covered is how you end up with a door your team did not know was standing open. The software firewall on laptop seven does not know what laptop three is doing. Your IT team needs the full picture.
What You Actually Need Stacked on Top of a Firewall
One.
That’s not a criticism. It wasn’t designed to do every job.
Think about securing a business after hours. You lock the front door, but you also lock the windows, set the alarm, keep the outside lights on, and make sure the person closing up doesn’t leave the back door standing open. No single lock protects the entire building.
Your network works the same way.
Here’s what every small business should have alongside a properly configured firewall:
- Endpoint Detection and Response (EDR) on every computer. Antivirus looks for what it recognizes. EDR watches for suspicious behavior, including threats nobody has seen before.
- Email filtering with sandboxing. Most attacks still begin with an email.
- Multi-factor authentication (MFA) on every internet-facing account. Every single one.
- DNS filtering to stop connections to known malicious websites before they happen.
- Security awareness training. Your employees are part of your security strategy. Once a year isn’t enough.
The NIST Cybersecurity Framework 2.0 breaks cybersecurity into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. A firewall helps with part of Protect, but it doesn’t Detect an attacker moving through your network, Respond to an incident, or Recover your data after an attack.
Digit’s Rule #11: “Probably fine” is a threat waiting for a timeline.
I hear it all the time.
“We have a firewall.”
Good.
What else do you have?
Because “we have a firewall” isn’t a security strategy any more than owning a smoke detector makes you prepared for a house fire. The businesses that treat a firewall as the finish line are usually the ones calling us on a Tuesday morning trying to figure out why they can’t open any of their files.
The Part Nobody Warns You About
Funny how that never makes it into the sales brochure.
A firewall isn’t something you install once and forget. Your business changes. You hire people, retire old computers, move applications to the cloud, add remote workers, replace software, and open new locations. Every one of those changes can affect the rules your firewall should be enforcing.
The firewall doesn’t know your business has changed.
It keeps following yesterday’s instructions until someone gives it new ones.
That’s why regular firewall reviews matter. You’re not just checking that the hardware still works. You’re making sure the rules still match the business they’re supposed to protect.
Digit’s Rule #19: Temporary has a funny habit of becoming permanent.
I’ve lost count of how many times I’ve seen a firewall rule that was supposed to be there for a week still sitting in place years later. Nobody meant for it to become permanent. Nobody remembered it was there.
The NIST Cybersecurity Framework recommends reviewing access controls and network configurations on a regular basis. There’s a good reason for that. Attackers aren’t the only ones changing your environment. Your own business is changing all the time.
Around 2 Dog Digital, we have a simpler way of describing those reviews.
We call them “finding out what changed when nobody told us.”
Where to Go From Here
You need a small business firewall. That is not negotiable. Configure it right. Review it regularly. Back it up with the layers that cover what it can’t.
Do this before you close this tab:
- Find out who set up your firewall and when someone last looked at the rules.
- Confirm it is sitting at your internet gateway. Not just running on individual machines.
- Pull the last thirty days of firewall logs. Ask your IT team what they see.
- No IT team? That’s the actual problem. Start there.
A small business firewall is not a ceiling. It is a floor. Build on it.
Businesses rarely get hit because they missed one giant project. It’s usually the small things that nobody went back to fix. A rule left open from a project that ended two years ago. An account that should have been disabled when someone left. Software nobody remembers installing. Small gaps have a way of becoming expensive ones when nobody is paying attention.
If you’re in the Triangle and you want to know whether your firewall is actually doing what you think it’s doing, we’ll take a look. Not to sell you a different firewall. To tell you the truth about the one you have.
If everything checks out, we’ll tell you that too. Either way you’ll know more than you did when you walked in. That’s worth thirty minutes.
Schedule a free consultation at 2dogdigital.com or pick up the phone and call us. We answer.
FAQ: Small Business Firewall Questions We Actually Hear
What does a firewall do for a small business?
A firewall sits at the edge of your network and monitors the traffic moving in and out. It blocks known malicious traffic, limits unauthorized access to your systems, and keeps logs your IT team can use when something doesn't look right. Think of it as the first line of defense, not the entire defense.
Does my small business need a firewall?
Yes.
Even a two-person business has computers, cloud accounts, and customer data worth protecting. A properly configured firewall reduces your attack surface and gives you visibility into what's happening on your network. Without one, you're relying on luck more than I'd recommend.
What can't a firewall protect against?
Quite a bit, actually.
A firewall can't stop someone from clicking a phishing link, plugging in an infected USB drive, or using a stolen password to log in. It also can't prevent an authorized employee from misusing legitimate access. That's why every business also needs endpoint protection, email filtering, MFA, and security awareness training.
Is Windows Firewall enough for my small business?
No. Full stop.
Windows Firewall protects the individual computer it's running on, and you should absolutely leave it enabled. What it doesn't do is protect your entire network. It can't provide centralized visibility, network-wide logging, or the security controls that a dedicated business firewall provides.
Do small businesses in Raleigh need a managed firewall?
If you don't have someone regularly reviewing firewall rules, logs, and security alerts, managed firewall services are worth a conversation. Technology doesn't stay secure because it's installed. It stays secure because someone is paying attention. At 2 Dog Digital, real people review your environment and keep it aligned with how your business actually operates. Not a dashboard. Not an alert nobody reads. Real people.