Your ISP Router Is Not a Firewall: What a Business Firewall Actually Stops
We got called to an accounting firm, eight staff, after their files turned into gibberish overnight and a note demanded payment to get them back. Ransomware. Nobody targeted them by name. A machine on their network had a service exposed to the internet with a weak password, a scanner found it (this happens within hours of anything going public), and that was the way in. We restored what we could from an old backup, but they lost the better part of two days and a chunk of recent work. The clean-up cost more than a firewall and proper backups would have, several times over.
They were not careless people. They had the box their ISP gave them and assumed that was protection. It is the most common misunderstanding we see, so it is worth being precise about what that box actually does.
What the ISP router does (and where it stops)
The router from Safaricom, Zuku, or Faiba does one useful security thing: NAT, which means devices inside are not each directly addressable from the internet by default. That blocks the crudest scans. It is a latch on the door, and for a home it is mostly fine.
What it does not do: it does not inspect traffic for known attacks, it does not filter malicious sites or command-and-control domains, it keeps no useful logs, it cannot separate your POS from guest Wi-Fi, and the moment someone forwards a port (for remote desktop, a camera app, a game) the latch is off and that service is exposed to the whole internet. Most breaches we clean up trace back to exactly that: a port opened for convenience and forgotten.
"We're too small to be a target"
Size is irrelevant because almost none of this is aimed. Bots scan every reachable address on the internet continuously, looking for open ports, default passwords, and unpatched systems. They do not know you are a small shop in Nairobi and they do not care. A compromised business router also gets quietly conscripted, used to relay other attacks or mine cryptocurrency, which is why your "slow internet" is occasionally a security problem wearing a disguise. You are not too small. You are just unprotected, which to a bot is the only thing that matters.
What a business firewall adds
- Real inbound control: deny everything by default, allow only what you actually need, and keep it that way instead of collecting forgotten open ports.
- Segmentation: POS on one segment, CCTV on another, staff on a third, guests walled off entirely. A guest's infected laptop then cannot reach your card terminal or your recorder.
- Content and DNS filtering: block known-malicious sites and the domains ransomware calls home to, often stopping an infection before it encrypts anything.
- Intrusion detection: spot and block traffic that matches known attack patterns.
- Logging: when something does go wrong, you can see what happened instead of guessing.
- Proper VPN: secure remote access for staff, so nobody needs to expose a service to the open internet to work from home.
The segmentation point is the one people underrate. A flat network, where the POS, the cameras, and the guest Wi-Fi all sit together, means one compromised device can reach everything. Splitting them is often the single highest-value change we make on a site.
What it costs
A business-grade firewall for a small office runs roughly KES 15,000 to KES 60,000 for the hardware, depending on user count and features. Setup is a one-time cost on top, and some units carry an annual licence for the live threat-intelligence and filtering feeds. Put that next to the accounting firm: two days down, lost work, recovery labour, and the quiet cost of clients wondering whether their data is safe. The firewall is the cheap side of that comparison every time.
The box matters less than the configuration
You do not need the most expensive firewall on the market. A modest, correctly configured unit beats an expensive one left on defaults. The value is in the rules: deny by default, open only what the business needs, segment the network, and keep the firmware and feeds current. A firewall installed and forgotten drifts back toward being an ordinary router. That ongoing configuration is the part worth paying someone to get right.
Want to know what's currently exposed on your network?
Get a security assessment