Your firewall is innocent - Troye
A firewall alone can't stop modern cyberattacks. See why cyber resilience, email security and MDR now matter more than perimeter defence.
Cyber resilience, cybersecurity, managed detection and response, MDR, email security, social engineering, firewall security, phishing protection, security operations, threat detection
11468
wp-singular,post-template-default,single,single-post,postid-11468,single-format-standard,wp-theme-bridge,bridge-core-3.3.2,qode-page-transition-enabled,ajax_fade,page_not_loaded,,qode_grid_1300,footer_responsive_adv,qode-content-sidebar-responsive,qode-theme-ver-29.5,qode-theme-bridge,qode_header_in_grid,wpb-js-composer js-comp-ver-8.0,vc_responsive
 

Your firewall is innocent

Cyber threats bypassing traditional perimeter defences as layered security detects and blocks attacks across users, devices and cloud systems.

Why perimeter defence isn’t enough anymore

Blaming the firewall when a cyberattack gets through is a little like blaming the front door when someone walks into your house wearing a uniform. The problem is not necessarily that the door failed, the problem is that someone found another way in.

Modern cyberattacks have become far too sophisticated for businesses to think of cybersecurity as a collection of products sitting behind a perimeter. The real challenge is detecting what looks legitimate, understanding what is actually happening and continuing to operate when something inevitably gets through.

Email as the weak point attackers exploit

Email is a good place to start because it remains one of the easiest ways for an attacker to exploit trust. Traditional spam filters were designed to identify unwanted messages, suspicious senders and known malicious content. That remains useful, but today’s attacks increasingly look like normal business communication.

A convincing request from a compromised supplier, an apparently legitimate document or a message that directs an employee to a familiar cloud service may sail straight past a conventional spam filter. The problem is no longer simply identifying junk mail. It is identifying deception.

Check Point Research’s Cyber Security Report 2026 found that social engineering remained a major attack vector in 2025. Attackers increasingly combined techniques across email, messaging and other collaboration platforms. Its AI Security Report 2026 also highlights how artificial intelligence is accelerating attackers’ ability to create and scale sophisticated campaigns.

That changes what organisations should expect from email security. Stopping spam is no longer enough. Security needs to understand behaviour, context, identity and intent.

Cybersecurity versus cyber resilience

But even the best email security cannot guarantee that nothing will get through. This is where the distinction between cybersecurity and cyber resilience becomes important. Cybersecurity reduces the likelihood and impact of an attack. Cyber resilience ensures the organisation can continue functioning when those defences are bypassed.

The World Economic Forum’s Global Cybersecurity Outlook 2026 found that only 19% of organisations surveyed believed their cyber resilience exceeded their requirements. That is a sobering statistic. It suggests that many businesses are still better at building walls than planning for what happens when someone climbs over them.

Resilience requires a different mindset. Consider a few scenarios. Can the business keep operating if ransomware takes down a critical system? Would the organisation contain a compromised executive’s account before an attacker moves further? Does anyone know which systems and data could be affected if a major supplier is breached? A firewall, endpoint security platform or email filter cannot answer these questions on its own. They require preparation, visibility and a response capability that extends beyond prevention.

Why Managed Detection and Response matters

This is also why Managed Detection and Response (MDR) is becoming increasingly relevant. The problem for many organisations is not a lack of security alerts. Rather, it is having too many of them and too few people with the time and specialist expertise to determine which ones deserve immediate attention.

IDC has highlighted the role of MDR in helping organisations address the growing complexity of threat detection and response, along with the shortage of specialist security skills. A security platform can tell you that something unusual happened. The value of an effective response capability lies in understanding whether it matters and doing something about it.

That distinction becomes particularly important outside office hours. Attackers do not work nine to five, and a suspicious login at 2am does not politely wait for the security team to arrive the next morning. MDR provides continuous monitoring, investigation and response. This helps organisations shorten the time between an attacker gaining access and someone taking action. It is not about replacing internal IT teams.

Instead, it extends their ability to deal with a threat environment that has become too fast, too complex and too persistent for many businesses to monitor alone.

Moving beyond a single-product mindset

Ultimately, cybersecurity is moving away from the idea that one product can solve one problem. Email security needs to recognise sophisticated social engineering. Detection needs to connect activity across users, devices and applications. Resilience needs to assume that something will eventually get through. MDR needs to turn the flood of security data into decisions and action.

The firewall can keep doing its job, just stop asking it to do everyone else’s. A resilient business is not one that never gets attacked. It’s one that can spot the attack, contain it, keep operating and recover without allowing one bad email to become a very good day for a cybercriminal.

By Troye Technical director Kurt Goodall