The firewall story for too many SMEs goes something like this:
Nobody discussed what firewall brand or model to buy, the features it has, or how it should be configured to provide actual protection.
The firewall was unboxed, and some basic configuration was applied so it passed traffic. Perhaps a VPN was setup to allow remote access – with little time spent thinking about how the firewall should be setup, monitored and updated after deployment.
Maybe it came from an old IT provider, maybe an internal IT engineer chose it. Maybe it’s even a decent bit of kit, from a well-known brand — at least on paper.
But here’s the reality:
If the device isn’t configured the way the manufacturer intended by somebody who understands what that means, and no one is actively managing , or monitoring that firewall, it can’t be protecting your business properly. It’s just sitting there – Ticking a box so you can say you have one. A recipe for disaster.
Static Firewalls Don’t Stop Dynamic Threats
The idea that a firewall is a ‘one-time fix’ activity is a myth. Modern cyber threats aren’t static. So why is your defence?
Too many businesses deploy firewalls to protect them from external threats, but don’t consider internal or dynamic ones. Ones where staff have mobile phones or other devices which connect to the private, internal network and reach out over the Internet for instructions. This is called command and control malware.
At Afinite, we routinely audit SME networks where a firewall is technically active — but:It hasn’t been updated regularly, either with new definitions or operating system patches
- It’s running default, basic or overly broad rules
- There are port forwarding rules which allow access to internal devices, but these overly board rules also allow anyone in the world with Internet access to connect your network
- ‘Advanced’ features like threat detection or geo-blocking are not configured
- No system or person monitoring traffic or reviewing logs
- No alerts are in place — so even if a threat was to be detected, no one knows
- There is no SSL inspection enabled
- The firewall is not providing any web filtering – no websites are filtered or blocked by the device leaving you at risk from phishing and other attacks
These are avoidable risks — but they’re surprisingly common because too many businesses are stuck in the ‘set and forget’ mindset.
This Is Where Palo Alto Networks Challenge the Approach
Palo Alto doesn’t treat firewalls as a static barrier. It treats them as a live, intelligent part of your security ecosystem.
That means:
- Constant, live visibility into what’s happening on your network
- Real-time threat detection powered by AI and cloud intelligence
- Granular control over traffic, users, and devices
- Integration with wider security policies and endpoints
- Automated updates to keep protections current
And while Palo Alto has a reputation for being an enterprise-grade solution, we’ve found it to be a powerful, flexible choice for SMEs too — provided it’s configured and managed appropriately.
Inside Palo Alto and The Tools That Make It Different
What separates Palo Alto from traditional firewalls isn’t just better performance — it’s a fundamentally smarter approach to protection.
- Strata Cloud Manager offers centralised, cloud-based control over your firewall environment. Apply policies, push updates, and monitor activity across one or multiple sites, all from a single, intuitive dashboard.
- Prisma Access extends protection to your remote users. Whether your team is working across multiple locations or logging in from home, Prisma ensures the same level of security and control applies everywhere — not just inside the office network.
- Precision AI, built into Palo Alto’s threat prevention tools, goes beyond signatures and static rules. It analyses patterns and behaviours in real time, detecting and blocking emerging threats before they become problems — and doing it faster than a human ever could.
If Your Firewall Is Passive, Your Risk Isn’t
It’s important to remember that your firewall isn’t a cyber security tick-box. It’s your first line of defence.
If it’s been left untouched since install day, it’s probably not doing what you think it is.
That’s why we work with SMEs to rethink what a firewall should be doing — and ensure that solutions like Palo Alto are configured to deliver real, proactive protection.
Free Palo Alto Consultation
If you’re unsure about your current firewall setup — let’s talk.
We offer a free Palo Alto consultation to help SMEs understand the gaps, explore smarter configuration options, and turn their firewall from a passive liability to proactive, robust part of your cyber security defences.



