Does a Small Business Need a Firewall? (Short Answer: Yes — Here's the Honest Long One)

Updated September 1, 2026

A locked padlock on a circuit background

The question usually arrives from outside. A cyber-insurance renewal asks whether you have a business-grade firewall. A new client's security questionnaire wants the make, the model and who manages it. Or an IT company quotes you a box with a three-year subscription attached, and you wonder — reasonably — whether you're being sold something. And your router's settings page says "Firewall" right there in the menu.

Here is the honest version. The firewall in your router is real, it does one job well, and for a certain kind of office it genuinely is enough. For most businesses it stopped being enough a while ago — not because a vendor says so, but because of how attacks actually arrive now.

What the router's firewall actually does

Nearly every router does two things that earn the name. The first is NAT — network address translation. Your whole office shares one public internet address, and the router keeps a ledger of which inside device asked for what. The useful side effect: traffic nobody inside asked for matches nothing in the ledger, so it gets dropped. The second is stateful inspection, a formal way of saying replies only get in if someone inside started the conversation.

That is genuine protection against one class of attack — strangers reaching in from the internet. The background scanning that rattles every public address on earth, all day, bounces off a NAT router without a sound. Anyone who tells you a plain router gives you nothing is overselling.

The part it cannot see

The trouble is that very little arrives as a stranger reaching in anymore. Attacks come the other way round: somebody inside clicks. A phishing email, a poisoned attachment, a fake invoice, a hijacked website — the click opens an outbound connection, and the router waves outbound traffic through without a glance. It always has. That is its job.

Once something is running on one machine, the router has no further opinion. It cannot see malware calling home, cannot stop it hopping to the PC beside it, keeps no record, and cannot tell you afterwards what left the building. Every device sits on one flat network, equally trusted — the front-desk PC, the bookkeeping PC, the cameras, and whatever a visitor's phone brought in with it.

What a real firewall adds

A business firewall — the kind that costs real money and comes with a subscription — changes four practical things.

  • Segmentation. Cameras, card terminals, guest Wi-Fi and office PCs go onto separate networks with rules about who may talk to whom, so a compromised camera can no longer reach the bookkeeping PC. It is the biggest single upgrade for most offices — more depth in our small office network guide.
  • A proper VPN. Staff working from home connect through an encrypted tunnel to the firewall instead of a port forwarded straight to a PC — the difference is the whole subject of remote access without opening a hole.
  • Filtering. Outbound traffic is checked against a continuously updated list of known-bad destinations, so malware that does get clicked often finds its call home blocked. You can also shut off whole categories you have no business reason to allow.
  • Logs. When something goes wrong, you can answer what happened, when, and from which machine. That is the difference between an incident and a mystery, and the first thing insurers and investigators ask for.

One thing to know before buying: the filtering and the threat intelligence live in an annual security subscription, not in the metal. Let it lapse and the box keeps routing while the protection quietly goes stale. Budget for the renewals or reconsider the purchase.

When the router honestly is enough

A four-person office where everyone works on a laptop, everything lives in Microsoft 365 or Google Workspace, nothing is hosted on site, no card terminals, no cameras, no records that privacy law cares about — that office is fine behind a decent current router with automatic updates on and a separate guest network. The realistic threats there are phishing and weak passwords, and a firewall stops neither. Spend the money on two-factor authentication and backups first; they sit near the top of the small business cybersecurity checklist for good reason.

The router stops being enough at recognisable moments. You start taking card payments. You keep client, patient or case records. A server or NAS moves into the closet. Cameras or door controllers join the network. Staff begin connecting from home. An insurer starts asking questions in writing. Any one of those is the moment — not a vague someday.

Sizing one without the jargon

Firewalls are sold on throughput, and the headline figure on the datasheet is the machine doing nothing useful. Switch on the inspection features — the reason you are buying it — and real-world speed drops to a fraction of that number. The only sizing rule that matters: the firewall must keep up with your internet connection with every protection feature turned on. Ask for the threat-protection figure and compare that one against your line speed.

Vendors' user counts are honest shorthand; for most small offices the choice lands between the small and middle model of whichever line the installer supports. Buying too small has a specific failure mode: the internet feels slow, the firewall gets the blame, and one day someone switches the inspection off to speed things up. At that point you own an expensive router.

A badly set-up firewall is worse than none

Worse, because having none keeps you appropriately careful, while a misconfigured one hands out confidence nothing is earning. The same findings turn up on assessment after assessment: a port forwarded for every app anyone ever had trouble with; the admin password still the default; the management page reachable from the open internet; an allow-everything rule added during some long-forgotten troubleshooting session and never removed; a security subscription that expired two office managers ago; logs no human being has ever read.

If a box was installed years back and nobody has touched it since, treat it as an unknown, not an asset. A configuration review takes a professional an hour or two. If you would rather have proof than reassurance, a penetration test checks from the outside what your network actually answers to — occasionally a very educational document.

The questionnaire is not going away

Cyber-insurance applications and client security questionnaires now ask about firewalls directly — make, model, who manages it, whether the subscription is current. The trap is answering yes because the router's settings page has a firewall tab. If a claim follows an incident, the insurer's assessors will establish what was actually deployed, and a misrepresented answer gives them a reason to fight the payout. Answering honestly and fixing the gap is cheaper than either outcome.

Card payments carry a version of the same obligation: the merchant agreement you signed commits you to the card industry's security standard, which expects card systems to be separated from the rest of your network. A flat network behind a home router does not honestly tick that box either.

Getting one specified and installed without the homework

Firewall specification and configuration is work Koadi Technology delivers end to end — choosing a right-sized unit, installing it, building the segmentation and VPN, and supporting it afterwards. Describe your office in plain words at post a problem — posting is free — and vetted, identity-verified technicians pick it up; you set a fixed price or take bids, and payment sits in escrow until you approve the finished work. Remote help covers every US state, and on-site visits are available through local technicians when someone needs to stand in front of the rack. If you would rather talk it through first: (848) 266-6363.

Frequently asked questions

Isn't the firewall built into my router enough for a small business?
It blocks strangers reaching in from the internet, and that part it does well. It cannot inspect outbound traffic, separate your devices from each other, or keep logs — and most modern attacks start with a click from inside. For a few laptops living in cloud apps it can be enough; add card payments, servers, cameras or remote staff and it isn't.
How much does a small business firewall cost?
Two parts: the hardware, sized to your user count and internet speed, and an annual security subscription that keeps the threat intelligence current. The subscription recurs for the life of the box, so compare total cost over three years rather than sticker prices, and get quotes for your actual office — size drives price more than brand.
Do we need a firewall if everything we use is in the cloud?
Less than most offices, honestly. If every worker is on a laptop, nothing is hosted on site and there are no card terminals or cameras, a well-kept router plus two-factor authentication and backups covers the realistic risk. The calculation changes the day you add on-site equipment, take card payments, or an insurer asks in writing.
What is network segmentation and does a small office need it?
Segmentation splits one flat network into separate zones — office PCs, cameras, card terminals, guest Wi-Fi — with rules about which zone may talk to which. It matters because whatever gets compromised first can then reach only its own zone. Any office with cameras, payment hardware or guest Wi-Fi benefits, and a firewall is the tool that enforces it.

Still stuck?

Post this problem on Koadi — a vetted technician picks it up in minutes, and you don't pay until it's fixed.

Get a tech on it
← All fix-it guides