“We already have a firewall, so we’re protected.” This is one of the most common assumptions in business IT, and it’s not entirely wrong. A firewall plays an important role in protecting the network perimeter and controlling traffic entering and leaving the environment. However, protecting the perimeter is only one part of a broader security picture.
Modern business environments extend far beyond the network itself. Employees work from laptops, access email and cloud applications, share files and handle business data across multiple platforms. That means there are other layers that also need attention: the devices your team uses, the people using them, the email they receive and the cloud data behind their logins.
That is not a criticism of firewalls. In fact, it is the opposite: a firewall does its job as one important layer of protection. The question is whether the layers around it are being protected, monitored and tested as well.
Where attacks actually land
If a firewall guards the perimeter, it helps to look at what sits behind it because that’s where other parts of the security picture come into play.
There are four layers worth looking at:
- The laptop or device someone is actually using. Is it patched? Does it have antivirus protection? Is anyone monitoring what it detects?
- The person sitting in front of that device. Would they recognise a convincing phishing attempt? Would they know what to do if one reached them?
- The email environment itself. How much suspicious or malicious email is getting through before a user even has to make a judgement call?
- Your Microsoft 365 environment. If something is deleted, compromised or needs to be restored, what protection and recovery options are in place?
These four are some of the layers that sit behind the firewall. None of them are new problems exactly. They are just the ones that tend to get the least attention because they don’t feel as urgent as “do we have a firewall” until something goes wrong.
The numbers actually back these up. Verizon’s 2025 Data Breach Investigations Report found that vulnerability exploitation was involved in 20% of breaches, up 34% from the previous year. The report also found that attackers could exploit some critical vulnerabilities much faster than organisations could remediate them
That gap matters. Knowing a vulnerability exists is one thing. Making sure the affected devices are patched is another.
The gaps are connected
Here’s the part that’s easy to miss: these are not four separate IT problems that happen to live in the same document. They are connected, and an attacker does not need to pick just one.
The unpatched device is one way in. A convincing enough email is another. The user having a busy morning and not looking closely enough at a link is a third. None of these necessarily require an attacker to “breaking through” the network perimeter. They can instead exploit gaps in the layers beyond it. That’s really the core idea: security is only as strong as the gaps between the layers, not just the strength of any one layer on its own. A great firewall next to an unpatched laptop and an untested inbox doesn’t actually add up to strong security. It just moves the weak point somewhere else.
Why visibility matters
This is where the idea of actually managing these layers together starts to matter, and it’s less about buying another tool and more about simply being able to answer a few honest questions.
Which devices are behind on patches right now, today, not whenever someone last checked? Are your users actually vulnerable to phishing, or is that just an assumption nobody’s tested? What’s getting through the inbox before a human even sees it? And if something important in Microsoft 365 disappeared tomorrow, deleted by mistake or by something worse, what would you actually be able to restore?
Not every business can answer all four of those with confidence, and that’s okay. The point isn’t to feel bad about it. It’s to recognise that these are answerable questions, and that having the answers changes how you can respond if something happens. Naming your actual security gaps is the first step to closing them, and a lot of businesses have simply never been asked to name them out loud.
On the user side specifically, the honest answer is usually better than people expect, which is exactly why it’s worth actually testing rather than guessing. Fortra’s 2025 Phishing Simulation Benchmark Report, based on over 14 million simulated phishing emails sent across more than 7,500 campaigns, found an average click rate of 5.42%. That sounds low, until you put it into perspective: roughly 1 in 20 employees in the benchmark clicked a simulated phishing email.
Four questions to ask about your current security setup
It’s worth turning that into something you can actually sit down and check for yourself.
On the endpoint side: can you see which devices aren’t fully patched or protected right now, across your whole fleet, not just the ones in the office?
On the user side: have you actually tested how your employees respond to a realistic phishing attempt, or is “they know not to click things” just an assumption everyone’s comfortable with?
On the inbox side: what happens to malicious email before it ever reaches a person, and how much of that filtering is actually happening versus just being turned on and forgotten?
And on the tenant side: if critical Microsoft 365 data got deleted, whether by accident or something more deliberate, what can genuinely be restored, and from where?
None of these have to have a perfect answer today. They just need an honest one.
There’s more to protection than the perimeter
It’s worth saying plainly: a firewall is one layer of your overall security strategy, not the entire strategy. That’s not a knock against firewalls, it’s just what they were built to do, and expecting them to cover everything else was never really fair to them in the first place.
This is where bringing these four layers together under one managed approach starts to make more sense than treating them as four separate purchases from four separate vendors. Instead of a patchwork of tools nobody’s fully accountable for, you get something closer to a single view: 24/7 monitoring, reporting you can actually read, and one provider you can call when something needs an answer. We won’t unpack exactly how all of that works here, because that’s genuinely worth its own conversation.
Where to start
If reading through those four questions left you a little unsure of a couple of the answers, that’s a completely normal place to be, and it’s also a useful starting point.
A short security review can walk through where your current security gaps might be: scoping a phishing simulation for your team, checking the patch and antivirus status across your devices, and taking an honest look at what your Microsoft 365 setup actually retains if something goes wrong. It’s a practical way to move from “we think we’re covered” to knowing where the gaps actually are.
Want to see where your security gaps might be?



