Call NowFree Quote
Cybersecurity

Network Security for Perth Businesses: Firewalls, VPNs and DNS Filtering

Most Perth businesses focus their security attention on email and endpoints - and for good reason. But the network itself is often overlooked. A poorly configured network means attackers who get in anywhere can move freely, access everything, and stay hidden for months. Here's what network security actually means for a Perth SMB.

Your Firewall - More Than Just the Router

Most Perth small businesses have a router supplied by their ISP with a basic built-in firewall. This provides minimal protection - it blocks obvious inbound attacks but does little else. A business-grade firewall does significantly more:

  • Deep packet inspection (DPI) - examines the content of network traffic, not just where it's going, catching malicious payloads inside otherwise legitimate-looking connections
  • Application awareness - identifies and controls specific applications using your network (blocking peer-to-peer file sharing, for example, while allowing business tools)
  • Intrusion Prevention System (IPS) - detects and blocks known attack patterns in real time
  • Outbound filtering - monitors traffic leaving your network, catching malware that's trying to call home or exfiltrate data

Business-grade firewalls from vendors like Fortinet, Cisco Meraki, or Sophos bring these capabilities to Perth SMBs at reasonable price points. They require proper configuration to be effective - a misconfigured business firewall can be worse than a simple consumer router.

Network Segmentation - Containing the Blast Radius

A flat network - where every device can communicate freely with every other device - means that if ransomware gets onto one machine, it can reach every other machine on the network almost instantly. Network segmentation divides your network into separate zones using VLANs (Virtual Local Area Networks):

  • Staff workstations - one segment for computers and laptops
  • Servers and NAS devices - a separate, tightly controlled segment
  • IoT and printers - isolated segment, as these devices are frequently vulnerable and rarely updated
  • Guest WiFi - completely separate from internal networks

With proper segmentation, a compromised workstation cannot directly reach your file server. The attack is contained rather than spreading freely.

DNS Filtering - Blocking Threats Before They Land

DNS filtering works at the earliest stage of any internet connection. When a device on your network tries to reach a website, it first looks up that website's address via DNS. DNS filtering intercepts that lookup and blocks known malicious domains before any connection is made - before any malicious file can be downloaded or any phishing page can load.

Solutions like Cisco Umbrella, Cloudflare Gateway, or similar provide DNS filtering that:

  • Blocks known malware distribution sites, phishing pages, and command-and-control servers
  • Can enforce category-based filtering (blocking adult content, gambling, or other categories on work networks)
  • Works even when staff are off-site on company laptops - the filtering follows the device, not just the office network
  • Provides visibility into what domains your network is querying, which can reveal infected devices trying to contact attacker infrastructure

DNS filtering costs $3–5 per user per month and is one of the highest-value, lowest-cost security controls available to Perth SMBs.

VPN - When You Actually Need One

VPNs are often recommended reflexively, but for cloud-first Perth businesses, they're not always necessary. The key question is: do you have on-premises resources staff need to access remotely?

  • If yes (on-premises server, internal file share, legacy accounting software running locally): a VPN is appropriate for remote access to those resources
  • If no (everything is in Microsoft 365, cloud-hosted SaaS): focus on MFA and Conditional Access instead - a VPN adds complexity without meaningful security benefit for cloud-only environments

When a VPN is needed, use a proper business VPN solution - not consumer products. Split tunnelling (where only traffic to internal resources goes through the VPN) reduces performance impact while maintaining security for on-premises access.

WiFi Security - Often the Weakest Link

Weak WiFi security is a common entry point for attackers, especially in open-plan offices or buildings with shared spaces. Key settings for Perth business WiFi:

  • WPA3 encryption - or at minimum WPA2-AES. Never WEP or WPA (TKIP).
  • Strong, unique SSID and password - not the default router name, not a generic password shared with everyone forever
  • Management interface not accessible from WiFi - your router's admin panel should only be reachable from a wired connection
  • Regular password rotation - change your staff WiFi password when an employee leaves
  • Separate guest network - as covered in our guest WiFi guide, visitors should never be on the same network as your business systems

Network Monitoring - Knowing When Something Is Wrong

Even well-secured networks get breached. The difference between a minor incident and a catastrophic one is often how quickly the breach is detected. Network monitoring tools watch for unusual traffic patterns - a workstation suddenly sending large amounts of data externally, unusual login attempts, connections to suspicious IP ranges - and alert your IT provider before the situation escalates.

Frequently Asked Questions

Isn't the firewall built into my internet router enough?

Not really, an ISP-supplied router's built-in firewall blocks obvious inbound attacks but does little beyond that. A proper business-grade firewall adds deep packet inspection, intrusion prevention, and outbound filtering that catches malware trying to send data back to an attacker, all things a basic router simply can't do.

Do we actually need a VPN if everything we use is already in the cloud?

Often not. If your business runs entirely on Microsoft 365 and cloud-hosted software with no on-premises server or internal file share, a VPN adds complexity without much security benefit, focus on MFA and Conditional Access instead. A VPN earns its place when staff genuinely need remote access to something still hosted on-site.

What is network segmentation and why does it matter for a small business?

It means splitting your network into separate zones, staff computers, servers, printers, and guest WiFi, using VLANs so a compromised device can't freely reach everything else. Without it, ransomware that lands on one workstation can often spread to your file server within minutes.

Is DNS filtering worth the cost for a small business?

Yes, it's one of the best value security controls available, typically $3-5 per user per month, and it blocks known malicious and phishing sites at the lookup stage before any dangerous file can even download. It also keeps working when staff are off-site on a company laptop, since the filtering follows the device rather than just the office network.

Firewalls, segmentation, and DNS filtering are all part of the network builds we design and manage for Perth businesses.

Network Setup →

Want a network security assessment for your Perth business?

Call 0433 087 091 - we'll review your firewall, WiFi, segmentation, and DNS filtering and tell you exactly where the gaps are.

Book a Network Assessment

For related reading, see our guides to Zero Trust Security for Perth Businesses, Email Security for Perth Businesses, and DNS Filtering for Perth Businesses.

Share this article