What does a router from the provider do?
Most small and medium-sized enterprises have equipment at the edge of their network supplied by the internet provider together with the connection. This equipment performs well in what it was designed for: it routes traffic between the internal network and the internet, performs address translation, and can set up port forwarding when the company needs external access to a camera or a remote server area.
The basic protection it offers is that no connection from outside will pass through unless requested by someone inside the network. However, its role usually ends there. It cannot look into the traffic that the company itself allows in or out, it cannot distinguish harmful content within an authorised connection, and it provides the administrator with no meaningful overview of what is happening in the network.
What real risks face small and medium-sized enterprises
There is no need to fear targeted attacks by state actors: the vast majority of problems faced by smaller companies are automated and indiscriminate. The main issues are as follows:
- Automated internet scanning that searches for open remote access points (RDP, remote administration) or outdated software with known vulnerabilities.
- Fraudulent emails attempting to extract login credentials or trick employees into opening attachments.
- Attacks that, once they breach the network, encrypt company data and demand a ransom for its restoration, even a smaller business can lose several days of operations as a result.
- Data leaks via a forgotten test system or an unsecured remote access exposed directly to the internet.
None of these incidents require someone to personally select the company. It is sufficient that the company is visible on the internet and has some vulnerability. Companies with ten or fifty employees often believe they are not interesting enough for an attacker, but from the perspective of automated scanning, company size does not matter; only whether an open opportunity is visible matters.
Why companies have long overlooked this
A typical reason why a company sticks with the router provided by its ISP is not laziness or ignorance, but simply the fact that the network has been functioning without visible problems for a long time. External access works, emails are delivered, and the printer is visible remotely. However, the risk does not manifest as a slowly rising graph, but as a one-off event that arrives without warning. Meanwhile, what the company exposes on the internet is also changing: remote access points increase, applications run outside the corporate network, and branches and suppliers gain access to the network. The ISP-provided router remains the same, while the area requiring monitoring grows.
What extra capabilities does a firewall offer?
A firewall operates differently from a simple router. Instead of merely allowing or blocking connections based on address and port, it also examines what is actually happening inside the connection. This is the basis of intrusion prevention (IPS), which we discuss in in a separate article on UTM functions.
- Network segmentation. Offices, production areas, guest networks or servers can be separated: a problem in one section will not automatically spread to the entire company.
- Secure remote access. Encrypted VPN replaces the risky practice of exposing an open port directly to the computer's desktop.
- Operational visibility. The firewall logs who connects where and what is operating unusually, allowing the administrator to react before damage occurs.
When does switching make sense?
The simplest way to verify this is to have the network examined from the outside, which ports and services are visible from the internet, what traffic passes without control, and where the company relies solely on the provider's equipment. Such an initial audit does not need to take long and can reveal whether the current state is still acceptable or if the company is already operating at the limit.
Only on this basis does it make sense to determine which firewall model and which specific functions are appropriate for the given operation. We address this in the article about FortiGate licensesThe transition does not necessarily require a large one-off investment: the hardware can be leased for a monthly fee, so the company does not pay for equipment it would otherwise have to buy all at once.