How Do You Firewall Your People? (Why a Firewall Isn’t Enough for Your Business Anymore)

Shield and digital lock graphic illustrating whether a firewall is enough to protect a small business from cyberattacks

You have a firewall and antivirus that's kept your business safe for years. There's a good reason you've never had to think much harder about security than that: for a long time, it really was enough.

But then, the types of attacks that businesses most often face changed. Today, the more common way into a business isn't a hacker breaking through a firewall from the outside. It's someone already inside the firewall clicking on something they shouldn't have. That single shift is what this article is about: why it happened, what it actually looks like in practice, and how to protect your business.

"A firewall and antivirus can't stop the people layer. In fact, nothing can stop the people layer." — Matt Griffin, Lead Technician

The Way IT Problems Actually Work: People, Applications, and Equipment

When something goes wrong with your business's IT, the problem is almost always in one of three places: the people using the systems, the applications running on them, or the equipment itself.

A firewall and antivirus are equipment-layer and application-layer tools. They're built to keep bad traffic out, patch known vulnerabilities, and stop malicious code from executing. That work still matters, and it's still necessary. But it was never designed to address the third layer: the people layer. And that's the layer attackers have increasingly learned to target instead.

Matt describes it as a diagnostic habit: when a problem is happening to everyone at once, it's usually an application or equipment issue. When it's happening to just one person, it's almost always something at the people layer instead, and that's exactly where a firewall has no reach at all.

The threat landscape has moved from equipment-layer attacks (breaking through a firewall from the outside) to people-layer attacks, which simply persuade someone already inside the firewall to open the door themselves. The firewall is still necessary. Unfortunately, on its own, it's no longer sufficient.

What Changed (and When It Changed)

This isn't a vague claim that "threats are evolving." There's a specific reason the people layer became the dominant target, and it traces back to the pandemic.

When offices sent everyone home, the tightly managed workflows businesses had relied on for years went with them. People started managing their own schedules, their own routines, and their own communication, mostly through email, since that became the default channel for almost everything. And attackers noticed. A workforce working from home, communicating primarily by email, and no longer working shoulder-to-shoulder with colleagues who might catch something unusual, created exactly the kind of opening a firewall was never built to close.

The shift to remote work created a new kind of vulnerability. Not in the technology itself, but in the daily habits of the people using it. Attackers adapted quickly. Imagine your accounts payable person: skilled, trusted, and very good at processing wire transfers quickly, because that's their job. Now imagine a fraudulent email lands in their inbox asking for exactly that: a wire transfer, urgent, from someone who appears to be a legitimate internal contact. Next thing you know, a wire transfer has been made that was not legitimate. That's often all it takes.

The scale of this shift shows up clearly in the numbers. The FBI's Internet Crime Complaint Center (IC3) received more reports of phishing and spoofing in 2024 than any other type of cybercrime it tracks (over 193,000 complaints in a single year) and total reported losses across all internet crime hit $16.6 billion, a 33% increase over the year before. Business email compromise alone, the exact kind of scheme aimed at your accounts payable person, accounted for billions of that total.

Why the Firewall Can't Stop This

It's worth being concrete about the mechanics here, not to turn you into a security engineer, but to convince you that "we have a firewall" is not a complete answer.

A firewall can be kept current. Known vulnerabilities can be patched, and Windows updates can be applied the day they're released. All of that is doable, and a well-managed IT setup does exactly that. But none of it matters the moment a person inside the network clicks the wrong link.

"It's the people clicking things that come in via email. If you don't have the correct hardening on that end, all the work that you did to get your firewall and antivirus square no longer matters because Bob clicked that link and we're done." — Matt Griffin

Once a malicious link or attachment is clicked, whatever comes next, whether it’s a credential theft, a piece of malware, or a ransomware payload, is already inside the perimeter the firewall was built to protect. In Matt's experience, two full ransomware takeovers happened in a single year at businesses he's worked with, and in both cases, the entire event traced back to one person clicking one link. That's not a reason for panic; it's a reason to understand exactly where the real exposure sits and do something about it.

What a Sophisticated Phishing Attempt Actually Looks Like

If your mental image of a phishing email is something obviously fake, like bad grammar, a stranger's name, or a prize you didn't enter to win, then it's worth updating that picture. The attempts that actually get through look nothing like that.

A well-constructed phishing email arrives looking exactly like an internal message. It carries the company's letterhead, the company's signature format, and the correct name and job title of a real colleague, right down to the smallest detail. The one thing that might give it away could be a single missing letter in a job title, easy to miss on a quick read.

The link inside often looks legitimate too, until you actually hover over it. What displays as a familiar, trusted address can redirect somewhere else entirely once you look at where it points.

A quality spam filter helps here, because it checks not just what an email claims to be from, but where it actually originated, and flags a redirect before a person ever gets the chance to click it. Some enterprise-grade spam filtering tools go a step further, holding the connection until an administrator reviews and approves it. But sophisticated attackers have found ways around even strong filtering, which is exactly why the hover-and-check habit still matters — no tool catches everything, and the person at the keyboard is genuinely the last line of defense. That's not a failure of the technology. It's the nature of the problem, and it's exactly why training matters as much as the tools themselves.

"We're Too Small to Be a Target" (and Why That's Exactly Wrong)

This is one of the most common assumptions small business owners hold, and it's absolutely backwards. The actual test is simple. Do you have a bank account? Do you have money moving through your business? If the answer is yes, you are a target. Company size has very little to do with it.

If anything, smaller businesses are more attractive to attackers, not less. They typically have fewer resources dedicated to defense and hold real financial and customer data all the same. CISA itself notes that small businesses are targeted precisely because they carry valuable information without the larger security budgets that bigger organizations have.

The routine, repetitive nature of certain roles makes this worse, not better. An accounts payable person who processes wire transfers as part of their normal, day-to-day workflow isn't a weak link because they're careless; they're a target because their job is, by design, to act quickly and routinely on requests that look legitimate. An attacker doesn't need to defeat a sophisticated technical defense. They need to find one person, in one routine, on one ordinary day.

What Good Protection Actually Looks Like, and Where to Start

This isn't a checklist to implement everything at once, and it isn't a product pitch. Good protection rests on three things working together: tools, training, and a plan.

Tools: Starting With Email

Email is the front door for most people-layer attacks, so it's the right place to start. The baseline worth aiming for isn't a spam filter that only catches the obvious stuff, such as flagging an email because it mentions a lottery windfall. A genuinely useful spam filter goes deeper: it checks where an email actually originated, scans the links inside it, and can flag or hold a redirect before anyone has the chance to click it.

That's a meaningfully different level of protection than what most out-of-the-box email security provides, and it's worth asking any IT provider exactly how deep their filtering goes.

Training: The People Layer Is a Practice, Not a Product

Even the best spam filter available will miss some attempts. The majority get caught, but not all of them, and it only takes one to do serious damage. That's why training is the direct complement to tooling, not an optional add-on.

The goal isn't a single onboarding session that checks a compliance box. It's an ongoing practice: helping your team recognize what a suspicious email actually looks like, building the habit of hovering over a link before clicking it, and making it completely normal to ask before acting on anything that feels slightly off. That last part matters more than it sounds. A culture that encourages asking first is one of the most effective and least expensive protections a business can build.

Plan: Make One Before You Need One

The easiest thing is to talk to us, make a plan. That's the bottom line." — Matt Griffin

Most small businesses don't have a written plan for what happens if an employee clicks a bad link. The real question isn't whether to have one. It's whether you want to build that plan now, calmly, or improvise one in the middle of an actual incident. Having that conversation before an incident, rather than during one, is the single most useful step available to almost any business reading this.

When Your Current Setup Is Actually Fine

Not every business needs the same level of protection, and it would be dishonest to pretend otherwise. A very small operation with no sensitive customer data, no financial transactions moving through email, and no remote staff genuinely carries a lower risk profile than a fifty-person professional services firm handling client financials every day.

But lower risk isn't the same as no risk, and most small businesses carry more exposure than they realize. A business email address alone is enough to make you a plausible target for a wire-transfer scheme like the one described earlier. The honest starting point isn't a prescription for a specific set of tools. It's a conversation.

The right sequence is to understand your actual risk profile before any tool or training program gets recommended. A business that's genuinely low-risk should walk away from that conversation with confirmation, not a sales pitch. A business that's been assuming it's fine, without ever actually checking, should walk away with a clear next step.

Your IT provider is part of this picture too. A provider who's disengaged or slow to respond isn't just an inconvenience. It can leave real security gaps unaddressed for longer than they should be.

One area worth a mention is how artificial intelligence is changing the threat landscape. It's a real and growing part of the conversation, but it’s also early in the game, so anyone offering a confident, prescriptive answer about exactly what to do about AI-driven threats right now is getting ahead of where the industry really is.

This article has focused on naming the shift and explaining why it matters, not on solving every piece of it. The specific attack methods small businesses are seeing most right now is worth a closer look, along with what a real incident response plan actually involves once you have one.

Not sure how much of this applies to your business? A free IT assessment takes about 30 minutes. You'll get a clear, honest picture of where your current setup has real gaps — and what's actually worth addressing first.

Book an IT Assessment

Frequently Asked Questions

Why is a firewall not enough to protect my business?

A firewall protects the equipment and application layers of your IT by keeping unauthorized traffic out and managing known vulnerabilities. It cannot stop an attack that arrives disguised as a legitimate internal email and relies on a person clicking a link or acting on a fraudulent request. That gap (the people layer) is now the primary way attackers get into small businesses, and no firewall, however well maintained, addresses it on its own.

What types of cybersecurity do small businesses need beyond a firewall?

Beyond a firewall and antivirus, the three things that matter most are: a genuinely robust spam filter that checks email origin and scans links rather than just flagging obvious spam; ongoing security awareness training that builds the habit of checking before clicking; and a written incident response plan so your business isn't improvising during an actual event. Tools reduce exposure, but people and a plan are what close the remaining gap.

How do hackers get past a firewall?

In most cases, they don't. They go around it. Rather than breaking through a firewall from the outside, attackers send a convincing, well-disguised email to someone inside the business and rely on that person clicking a link or acting on a fraudulent request. Once that happens, the attacker is already inside the network the firewall was protecting, and the firewall itself becomes irrelevant to what happens next.

Scroll to Top