Key takeaways
- A consumer or ISP router only blocks unsolicited connections. It cannot see what is travelling through it.
- A next-generation firewall (NGFW) inspects applications, users and content — and blocks threats hidden inside normal-looking traffic.
- Most attacks on small businesses arrive through email, web browsing and remote access — exactly the traffic an NGFW controls.
- Choose on throughput with security features switched on, not the headline number on the box.
Your router is not a firewall
Almost every office we visit for the first time has the same setup: an internet router supplied by the provider, maybe a Wi-Fi extender, and a belief that "the router has a firewall". Technically it does — but it is the most basic kind. It uses stateful packet filtering: it remembers which connections were started from inside your network and drops anything unsolicited coming from outside.
That was enough in 2005. Today almost every attack rides in on a connection that you started: an employee opens an email attachment, visits a compromised website, or logs in to a fake Microsoft 365 page. To a basic router, all of that looks like perfectly legitimate outbound web traffic on port 443. It waves it straight through.
What makes a firewall "next-generation"
A next-generation firewall does everything a traditional one does, then adds layers that look inside the traffic:
- Application awareness. It recognises WhatsApp, Dropbox, TeamViewer or BitTorrent regardless of port — so you can allow Microsoft Teams but block unknown remote-control tools.
- Intrusion prevention (IPS). It matches traffic against thousands of known attack signatures and blocks exploit attempts against your servers and devices in real time.
- Web and DNS filtering. Malicious, phishing and newly registered domains are blocked before the page even loads.
- Malware and sandbox inspection. Files downloaded or received are scanned — and suspicious ones detonated safely in a sandbox.
- SSL/TLS inspection. Over 90% of web traffic is encrypted. Without decrypting (selectively and legally), a firewall is blind to most threats.
- User identity. Rules are written for people and groups — "Accounts can reach the ERP, guests can reach the internet only" — not just IP addresses.
Why small businesses are the main target
Attackers rarely pick victims by name. They run automated campaigns that scan the entire internet for weak points and send millions of phishing emails, then exploit whoever falls through. Smaller organisations are attractive precisely because they usually have:
- No dedicated security staff watching alerts.
- Remote-desktop or camera systems exposed directly to the internet.
- Flat networks, where one infected laptop can reach every server.
- Backups stored on the same network as the data they protect.
The result is predictable: a single compromised account becomes a ransomware incident that stops sales, payroll and deliveries for days. A properly configured NGFW breaks several links in that chain — blocking the phishing site, the malware download, the command-and-control connection and the attempt to move sideways through the network.
What a good deployment looks like
The hardware matters less than how it is configured. In our deployments we treat the firewall as the control centre of the whole network:
- Segment first. Staff, servers, guests, cameras and point-of-sale each get their own zone, and the firewall decides who may talk to whom. (See our guide to network segmentation with VLANs.)
- Default-deny between zones. Only the traffic the business actually needs is allowed. Everything else is blocked and logged.
- Close inbound exposure. No remote desktop, camera or NAS ports open to the internet. Remote staff connect through an encrypted VPN with multi-factor authentication.
- Turn the security services on. IPS, web filtering, anti-malware and application control — with subscriptions kept current.
- Watch it. Logs and alerts go somewhere a human will actually see them, and firmware is patched on a schedule.
How to choose the right firewall
| Question | Why it matters |
|---|---|
| Threat-protection throughput | The number on the box is usually measured with security features off. Size the device on IPS + anti-malware throughput at your real internet speed — with room to grow. |
| Number of users and sites | VPN users, branch tunnels and concurrent sessions all consume capacity. |
| Security subscriptions | Signatures and filtering databases need renewing. Budget for the licence, not just the hardware. |
| Management & reporting | Clear dashboards and alerts mean problems get noticed — and that you can prove compliance. |
| High availability | If the firewall fails, the business goes offline. Critical sites should consider a redundant pair or a fast-replacement plan. |
The bottom line
A next-generation firewall will not stop every possible attack — nothing does. But it turns your network from an open plan into a building with locked doors, ID badges and cameras. Combined with multi-factor authentication and tested backups, it removes the vast majority of the risk that takes small businesses offline.
If you are not sure what is protecting your network today, that is the first thing we check in a free IT assessment.



