My Business Growth Kit

Defensive tools

Does a small business actually need a firewall?

8 September 2026 · 6 min read

Somebody has quoted you for a firewall appliance and a yearly subscription, and you cannot tell whether it is essential or expensive theatre. For most small businesses in 2026 it is closer to theatre than the person selling it will admit — but not for the reason you would guess.

You already have a firewall

Your internet router has one, and it has been running since the day it was plugged in. Every laptop in the building has a second one, on by default in both Windows and macOS. Nothing arriving from the internet reaches a machine on your network unless something inside asked for it.

That is the job a firewall does, and for a business with no publicly reachable servers it is largely already done. The quote in front of you is not for a firewall. It is for a device that inspects traffic and enforces policy, which is a different product with a similar name.

The question that decides it

Ask one thing: does anything at your office need to be reachable from the internet?

  • An on-premises server that staff connect to remotely
  • A point-of-sale or booking system that suppliers reach directly
  • CCTV, door entry or building systems with remote access
  • A VPN that terminates at your office

If the answer is genuinely no — your files are in Microsoft 365, Google Workspace or Dropbox, your accounting is a website, and everyone works on laptops — then the perimeter the appliance is designed to defend does not really exist. Your data is not behind your front door. It is in somebody else's data centre, reached from wherever your staff happen to be.

Where an appliance does earn its cost

There are real cases, and they are worth naming plainly rather than dismissing.

You have on-site systems that must be reachable

Anything exposed to the internet needs something in front of it, and consumer routers are poor at this. A proper firewall with logging is the right tool.

You are regulated, or your customers audit you

If you handle card data, health records or defence work, a named control may be required regardless of whether it is the most effective use of the money. Compliance and security overlap but are not the same thing, and pretending otherwise fails audits.

You have equipment that cannot be patched

Medical devices, industrial controllers, older machines running software that will never be updated. These genuinely need something isolating them, because they cannot defend themselves.

Guest wifi is the common middle case. You do not need an appliance for it — you need your guest network genuinely separated from the network your own machines use, which most business routers can do already and which is worth checking today.

What actually gets attacked

Small businesses are rarely breached through the network perimeter. Attacks arrive by the routes nobody quotes for:

How it actually startsWould a firewall stop it?
Someone types their password into a fake login pageNo — the traffic is normal outbound web browsing
A password reused from a leaked site is tried on your emailNo — the attacker signs in from their own machine, not yours
An invoice attachment carries malwareRarely — it arrives over encrypted email
A supplier is compromised and emails you from a real accountNo
An ex-employee's account was never disabledNo

That is not an argument that firewalls are useless. It is an argument that the perimeter is not where your risk is concentrated, and that buying protection for the wrong place is a common and expensive mistake.

What to buy instead, in order

If you have a fixed budget and no on-site servers, this ordering buys more security per pound than an appliance.

  • Multi-factor authentication on everything, starting with email and your domain registrar. Hardware keys or passkeys if you can, app codes if you cannot. This single control blocks the majority of real small-business compromises.
  • A password manager for the whole team. The reason people reuse passwords is that remembering unique ones is impossible. Solve the cause.
  • Automatic updates, verified. Not assumed — actually checked, on every machine, once a quarter.
  • Backups you have restored from. An untested backup is a hope, not a control.
  • A written offboarding checklist so leavers actually lose access.

Work down that list before you work up to hardware. If you have done all five and still have budget, then the appliance conversation is a reasonable one to have.

How to answer the salesperson

Ask which specific attack the device would have stopped, given that your data sits in cloud services and your staff work remotely. It is a fair question with a real answer in some environments.

If the reply is about compliance, ask which framework and which control — that is checkable. If it is about "advanced threats" without naming one, you are being sold a feeling.

All articles