Most small businesses run antivirus software and have a firewall in place. But there’s a good chance someone along the way let you walk away thinking those two things had you covered. And if you’ve had a nagging feeling they might have oversold it a little? You aren’t wrong.
Let’s break down what these tools can do and where they stop working.
What Antivirus Does and Doesn’t Do
Antivirus software works by scanning files and comparing them against a database of known threats. When something matches, it blocks it or removes it. The problem is that most attacks hitting small businesses today don’t involve files at all.
For example, think about what happens in a phishing attack. An employee gets an email, clicks a link, and types their password into a fake login page that looks exactly like your Microsoft 365 portal. No file was downloaded, and nothing was installed. The antivirus saw nothing, because there was nothing to see. The attacker now has a valid username and password and logs in the same way your employee would.
There’s also the problem of new threats. A piece of malware written last week that hasn’t made it into any database yet won’t be found by the antivirus software. Additionally, fileless malware, which runs entirely in memory without ever installing a file on your system, gets through. Or a legitimate software update from a vendor you trust that’s been tampered with gets through because it looks legitimate and your antivirus treats it that way.
Modern antivirus is reactive, not proactive. It can only protect against threats it already knows about. Attackers know this too, so many of them have shifted to techniques that don’t appear to be threats to a signature-based scanner.
None of this means antivirus is worthless. It still catches plenty of known, everyday threats, and you should keep it running. But relying on it as your main line of defense is a bit like having a bouncer who only stops people on a list from 2010.
What a Firewall Does and Doesn’t Do
A firewall monitors traffic entering and leaving your network and applies rules to determine what gets through. A well-configured firewall is an important part of your setup, because it keeps unauthorized external traffic from knocking on your internal doors.
What it doesn’t do is protect you from traffic that doesn’t appear to be a threat.
Phishing emails also bypass firewalls entirely. They target the human layer, your employees, rather than coming through the network perimeter. It comes through someone’s inbox, and when they click the link, the damage starts on the device itself, behind the firewall.
And once an attacker has valid credentials, whether stolen through phishing, bought on the dark web, or picked up from a breach at some other site your employee used the same password on, they don’t need to break through your firewall at all. They log in through the front door, the same way your employees do. Â This could be through a VPN connection, a remote desktop session, or a cloud application your team uses every day. The firewall sees authorized traffic and waves it through. It has no way of knowing the person on the other end isn’t actually your employee.
Firewalls also can’t monitor what happens inside the network once someone is in. They don’t track lateral movement, suspicious behavior by authenticated users, or anything that happens between systems once the perimeter has been crossed. This is why network segmentation matters so much, and why an attacker who gets past the perimeter can often move through a flat internal network without ever triggering a firewall rule.
In our home analogy, the firewall protects your front door. Most modern attacks aren’t coming through the front door.
Wondering what’s getting through your current defenses? A penetration test shows you what an attacker would find, and how far they’d get. Talk to MainNerve about what that would look like for your environment.
 Â
So What Does Actually Help?
The goal here isn’t to make you feel like everything you’ve spent has been wasted. Antivirus and a firewall are a starting point, and keeping them is still the right call. The problem is treating them as a complete security posture when they’re really just the foundation. Here’s what fills the gaps they leave open.
Start by implementing the 5 security fixes for small businesses. Then hold regular, brief phishing conversations with your team to address the attack vector that bypasses every technical control you have in place. Â Finally, identify what is on your network, including the shadow IT your employees have been adding.
The last one is where we come in. A penetration test tells you whether your current defenses hold up against someone trying to get through. We’ve found many vulnerabilities in environments where antivirus was installed, firewalls were running, and everyone assumed security was handled. Finding that out from us is a considerably better outcome than finding it out from an attacker.
The Takeaway
Antivirus and a firewall are table stakes. They were good enough when most threats involved malicious files coming through email attachments, and they still serve a real purpose in a layered security program today. The issue is that the threat landscape has shifted, and the attacks hitting small businesses right now are specifically designed to exploit the blind spots those tools leave wide open.
What many small businesses lack is monitoring, response capability, trained employees, and tested defenses. They assume that because the tools were running and they are a small business, the protection is real.
The businesses that tend to come out the other side of a breach, or avoid one altogether, aren’t necessarily the ones with the most expensive tools. They’re the ones that understood what their tools could and couldn’t do, filled the gaps that mattered most for their specific environment, and stopped treating security as something that runs quietly in the background while everyone assumes it’s handled.
If you want to know where your gaps are, we’re glad to help you find out. MainNerve has been doing this work for over 20 years. Contact us today for a free consultation.