Most small businesses have the baseline: antivirus on the workstations, a firewall at the edge, and some version of MFA on email. That’s a start. It’s also roughly where the average ransomware victim was before they got hit.

The gap between “we have security tools” and “we have a security program” is filled by the layers most businesses skip — not because they’re expensive or exotic, but because nobody walked them through the full picture and explained what was missing.

Here are five of the most common gaps we find in new client environments.

Layer 1: DNS-Layer Filtering

Your firewall blocks traffic at the network level. DNS filtering operates differently: it intercepts domain name lookups before a connection is ever established, blocking access to malicious sites, phishing domains, and unauthorized categories of content at the query level.

The practical value is significant. Phishing sites that rotate domains constantly can evade traditional blacklists — DNS filtering with real-time threat intelligence catches newly registered malicious domains that haven’t made it onto static block lists yet. It also provides visibility into what your users are trying to reach, which is useful both for security monitoring and for surfacing shadow IT.

We integrate Advanced DNS Security into our standard managed services stack because it closes a real gap without adding meaningful complexity.

Layer 2: Email Security Beyond the Built-In Filter

Microsoft 365 includes Exchange Online Protection, and higher-tier licenses add Defender for Office 365. These catch a lot. They don’t catch everything — and what they miss tends to be the sophisticated, targeted attacks that cause the most damage.

Business Email Compromise (BEC) is the clearest example. A well-crafted BEC email impersonating a managing partner, an escrow company, or a vendor doesn’t contain malware or a phishing link — it’s just a convincing email asking someone to change a wire transfer destination. Standard filters aren’t designed to catch that.

Our Advanced Email Security solution, which we deploy for clients who handle high-value financial transactions or sensitive client communications, adds a layer of AI-based analysis that examines email content, sender behavior patterns, and communication context. For Miami law firms managing real estate closings or international transactions, a single intercepted BEC attempt justifies years of the subscription cost.

Layer 3: Endpoint Detection and Response (EDR)

Traditional antivirus is signature-based: it checks files against a known list of malicious patterns. Modern attacks frequently use legitimate system tools — PowerShell, WMI, remote management software — in ways that don’t trigger signature detection at all.

EDR monitors endpoint behavior rather than file signatures. It looks for the patterns of attacker activity: lateral movement, credential dumping, persistence mechanisms, attempts to disable security tools. Our Managed EDR platform, which we run on every managed endpoint, includes a 24/7 SOC that reviews flagged activity and escalates to us when human judgment is needed.

The combination of behavioral detection plus expert human review catches what signature-based tools miss — and catches it early, before ransomware is deployed or data is exfiltrated.

Layer 4: Privileged Access Controls and Identity Protection

Most small business environments were provisioned with convenience in mind: admin accounts used for daily work, shared credentials for certain systems, service accounts with domain admin rights because it was easier to set up that way. That configuration is a gift to attackers.

Microsoft Entra ID (formerly Azure AD) P2 licensing includes Privileged Identity Management (PIM), which allows admin rights to be granted just-in-time rather than persistently. Instead of an account having permanent admin access that an attacker could abuse, access is requested, approved, and time-limited. Entra ID P2 also includes Identity Protection, which provides risk-based conditional access — flagging and challenging logins that deviate from normal patterns.

For M365 environments, we configure Entra ID conditional access and privileged access controls through our M365 management platform. It’s often a matter of enabling and configuring capabilities that are already included in existing licensing.

Layer 5: Security Awareness Training That Actually Runs

Security awareness training that runs once a year at onboarding is essentially a compliance checkbox. It doesn’t change behavior. What changes behavior is repeated, relevant, and occasionally surprising.

Simulated phishing campaigns — where employees receive realistic but fake phishing emails and get immediate feedback when they click — are consistently more effective at changing behavior than any training module. The surprise of nearly falling for one is a more powerful lesson than a PowerPoint about what phishing looks like.

Our security awareness training platform runs continuously across our client base. Campaigns are tailored to the industry — for law firms, that means simulations that mimic the kinds of emails attorneys actually receive: vendor payment requests, opposing counsel file shares, court notification spoofs.

Putting the Layers Together

None of these five controls require building a security operations center. They’re additions to a managed services engagement that layer onto what most businesses already have. The combined cost for a business with 20-25 users is typically in the range of a few hundred dollars per month — less than the deductible on a cyber insurance claim, and significantly less than the cost of a ransomware recovery.

If you’d like to know which of these your current environment is missing, we can walk through an assessment. Most clients are surprised by how much is either already licensed and unconfigured, or available as a modest add-on to their existing setup.