833-847-3280
Schedule a Call

Good Tools, Wrong Threats: Why Your Security Setup May Be a Step Behind.

Most small businesses run antivirus software and have a firewall in place. But there’s a good chance someone along the way let you walk away thinking those two things had you covered. And if you’ve had a nagging feeling they might have oversold it a little? You aren’t wrong.

Let’s break down what these tools can do and where they stop working.

 

What Antivirus Does and Doesn’t Do

Antivirus software works by scanning files and comparing them against a database of known threats. When something matches, it blocks it or removes it. The problem is that most attacks hitting small businesses today don’t involve files at all.

For example, think about what happens in a phishing attack. An employee gets an email, clicks a link, and types their password into a fake login page that looks exactly like your Microsoft 365 portal. No file was downloaded, and nothing was installed. The antivirus saw nothing, because there was nothing to see. The attacker now has a valid username and password and logs in the same way your employee would.

There’s also the problem of new threats. A piece of malware written last week that hasn’t made it into any database yet won’t be found by the antivirus software. Additionally, fileless malware, which runs entirely in memory without ever installing a file on your system, gets through. Or a legitimate software update from a vendor you trust that’s been tampered with gets through because it looks legitimate and your antivirus treats it that way.

Modern antivirus is reactive, not proactive. It can only protect against threats it already knows about. Attackers know this too, so many of them have shifted to techniques that don’t appear to be threats to a signature-based scanner.

None of this means antivirus is worthless. It still catches plenty of known, everyday threats, and you should keep it running. But relying on it as your main line of defense is a bit like having a bouncer who only stops people on a list from 2010.

 

What a Firewall Does and Doesn’t Do

A firewall monitors traffic entering and leaving your network and applies rules to determine what gets through. A well-configured firewall is an important part of your setup, because it keeps unauthorized external traffic from knocking on your internal doors.

What it doesn’t do is protect you from traffic that doesn’t appear to be a threat.

Phishing emails also bypass firewalls entirely. They target the human layer, your employees, rather than coming through the network perimeter. It comes through someone’s inbox, and when they click the link, the damage starts on the device itself, behind the firewall.

And once an attacker has valid credentials, whether stolen through phishing, bought on the dark web, or picked up from a breach at some other site your employee used the same password on, they don’t need to break through your firewall at all. They log in through the front door, the same way your employees do.  This could be through a VPN connection, a remote desktop session, or a cloud application your team uses every day. The firewall sees authorized traffic and waves it through. It has no way of knowing the person on the other end isn’t actually your employee.

Firewalls also can’t monitor what happens inside the network once someone is in. They don’t track lateral movement, suspicious behavior by authenticated users, or anything that happens between systems once the perimeter has been crossed. This is why network segmentation matters so much, and why an attacker who gets past the perimeter can often move through a flat internal network without ever triggering a firewall rule.

In our home analogy, the firewall protects your front door. Most modern attacks aren’t coming through the front door.

 

Wondering what’s getting through your current defenses? A penetration test shows you what an attacker would find, and how far they’d get. Talk to MainNerve about what that would look like for your environment.

  

So What Does Actually Help?

The goal here isn’t to make you feel like everything you’ve spent has been wasted. Antivirus and a firewall are a starting point, and keeping them is still the right call. The problem is treating them as a complete security posture when they’re really just the foundation. Here’s what fills the gaps they leave open.

Start by implementing the 5 security fixes for small businesses. Then hold regular, brief phishing conversations with your team to address the attack vector that bypasses every technical control you have in place.  Finally, identify what is on your network, including the shadow IT your employees have been adding.

The last one is where we come in. A penetration test tells you whether your current defenses hold up against someone trying to get through. We’ve found many vulnerabilities in environments where antivirus was installed, firewalls were running, and everyone assumed security was handled. Finding that out from us is a considerably better outcome than finding it out from an attacker.

 

The Takeaway

Antivirus and a firewall are table stakes. They were good enough when most threats involved malicious files coming through email attachments, and they still serve a real purpose in a layered security program today. The issue is that the threat landscape has shifted, and the attacks hitting small businesses right now are specifically designed to exploit the blind spots those tools leave wide open.

What many small businesses lack is monitoring, response capability, trained employees, and tested defenses. They assume that because the tools were running and they are a small business, the protection is real.

The businesses that tend to come out the other side of a breach, or avoid one altogether, aren’t necessarily the ones with the most expensive tools. They’re the ones that understood what their tools could and couldn’t do, filled the gaps that mattered most for their specific environment, and stopped treating security as something that runs quietly in the background while everyone assumes it’s handled.

If you want to know where your gaps are, we’re glad to help you find out. MainNerve has been doing this work for over 20 years. Contact us today for a free consultation.

Latest Posts

A transparent image used for creating empty spaces in columns
The National Cybersecurity Alliance, working with CISA, surveyed 1,000 small business leaders across 10 industries. The results describe a false sense of security that’s remarkably consistent across small businesses of every size and industry. The study found that 86% of small businesses feel confident about…
A transparent image used for creating empty spaces in columns
Most of the security advice you’ve heard about protecting your Microsoft 365 accounts includes using a strong password and turning on MFA. That combination stops the vast majority of credential-based attacks, and it’s still good advice. EvilTokens is a good reason to understand where that…
A transparent image used for creating empty spaces in columns
McKesson is one of the largest healthcare companies in the United States. It distributes pharmaceuticals and medical supplies to hospitals, pharmacies, and clinics nationwide. Like most companies of its size, the data behind all of is stored in enterprise cloud platforms. The recent breach contains…
A transparent image used for creating empty spaces in columns
If your business uses any identity or age verification service, you should know about the IDScan.net breach. Not just as news, but as a direct example of how third-party vendors can be a risk for your organization.   Here’s What Happened A dark web identity-theft…
A transparent image used for creating empty spaces in columns
We don’t usually write about news that’s still developing, but what came out of Black Hat 2026 last month is directly relevant to any business evaluating AI tools, working with AI vendors, or considering where AI fits within their operations. Let’s take a look at…
A transparent image used for creating empty spaces in columns
Six months into 2026, the breach numbers were already worse than last year. And last year was a record from the year before. According to the Identity Theft Resource Center (ITRC), a nonprofit that tracks publicly reported breaches and assists victims of identity theft, U.S.…
contact

Our Team

This field is for validation purposes and should be left unchanged.
Name(Required)
On Load
Where? .serviceMM
What? Mega Menu: Services