
Choosing a firewall for your SMB
For a small or growing business, the firewall is the front door to your network. Pick the wrong one and you either overspend on capacity you'll never use or, worse, leave gaps that a basic router was never designed to cover. Here's how to think about the choice in plain terms.
What a modern firewall actually does
The word "firewall" undersells it. A consumer router blocks unsolicited traffic and calls it a day. A business firewall — often called a next-generation firewall (NGFW) — does considerably more:
- Inspects traffic, not just ports, so it can recognise applications and threats rather than blindly allowing anything on port 443.
- Filters content and known-bad destinations, reducing exposure to malware and phishing sites.
- Segments your network, keeping guest Wi-Fi, payment systems, and staff devices apart.
- Terminates VPNs so remote staff connect securely.
- Logs and alerts, giving you a record of what happened when something looks wrong.
Questions that actually determine the right size
Vendor spec sheets are full of throughput numbers. Most of them don't matter until you've answered these:
- How many people and devices? Headcount, plus phones, cameras, printers, and anything else on the network.
- What's your internet speed? A firewall that can't keep up with your line becomes the bottleneck — especially with inspection turned on.
- Do you have remote or hybrid staff? That pushes VPN capacity up the priority list.
- Any compliance obligations? Healthcare, payments, and similar contexts come with specific requirements.
- Who will run it? A powerful firewall nobody configures or updates is just an expensive paperweight.
The mistakes we see most
- Buying on throughput alone. The headline number is usually measured with all the security features off. Turn on inspection and real-world throughput drops — sometimes by half or more.
- "Set and forget." Firmware goes out of date, rules accumulate, and nobody reviews them. A firewall is a system to maintain, not an appliance to install once.
- Flat networks behind a good firewall. If everything inside is on one segment, a single compromised device reaches everything. Segmentation matters as much as the box itself.
- Ignoring the licence. The security features that make an NGFW worth buying are usually subscription-based. Budget for the renewal, not just the hardware.
The firewall is only as good as the configuration behind it and the discipline to keep it current.
A sensible approach
- Size for your internet speed and device count with inspection enabled, plus some headroom for growth.
- Use it to segment the network — at minimum, separate guest, staff, and any sensitive systems.
- Treat it as managed: scheduled firmware updates, periodic rule reviews, and monitoring of its alerts.
- Pair it with the basics it can't do alone — endpoint protection, backups, and user awareness.
Where we fit
Choosing, deploying, and maintaining firewalls is part of our cybersecurity service — including the ongoing work of keeping them current rather than just installing and walking away. If you're not sure what size fits your business, tell us about your setup and we'll point you in the right direction.
Have a project in mind?
Tell us what you're planning and our team will follow up with next steps.