Pro Blog | PK Tech

Email Security Threats That Firewalls Miss for Small Business

Written by Jordan Hetrick | August 10, 2026

 Small business owners tend to treat a firewall as the finish line for cybersecurity. Install it, point it at the network, and move on to the actual work of running the company. That assumption costs real money, and it leaves a wide-open gap in email security. In 2025, business email compromise alone generated $3.046 billion in reported losses in the United States, according to the FBI's Internet Crime Complaint Center. Almost none of that damage came from malware that a firewall could catch. It came from emails that looked completely normal. 

A firewall inspects traffic crossing a network boundary. It looks for known bad signatures, blocks suspicious IP ranges, and stops certain file types from passing through. That's a useful job, but email fraud rarely triggers any of those alarms. The attacker sends a clean message from a legitimate-looking address, asks a person to make a decision, and waits. There's no payload to scan and no malicious domain to flag. The FBI's data shows nearly 85 cents of every dollar lost to cybercrime last year came from cyber-enabled fraud, where criminals manipulate a person into a decision rather than breaking a technical control. This is the gap small businesses need to understand, and it's exactly where managed cybersecurity services earn their keep.

Business Email Compromise Doesn't Look Like an Attack

Business email compromise, or BEC, is a scam built entirely around trust. An attacker either takes over a real email account or registers a domain that closely resembles a vendor's or executive's address. Then they wait for the right moment, such as a wire transfer, a vendor payment, or a payroll change. According to CISA, criminals research a company's communications and travel schedules after compromising an account, then send fraudulent wire instructions once they understand how the business actually operates. The spoofed address is often a single character off from the real one, easy to miss on a phone screen between meetings.

Small businesses assume this happens to larger companies with bigger bank accounts. That's backward. CISA notes that small and mid-sized businesses are especially vulnerable precisely because they don't have the staff or budget to build the verification steps that larger finance departments take for granted. A twelve-person company with one bookkeeper and no second approver for wire transfers is an easier target than a bank with a four-person compliance team reviewing every transaction over $10,000.

Phishing Has Outgrown the Filters Built to Stop It

Standard email filters were designed around a phishing email that looked obviously fake: broken English, a suspicious link, and an attachment named "invoice.exe." That version of phishing still exists, but it's no longer what's driving losses. Microsoft's threat intelligence team detected roughly 8.3 billion phishing threats in a single quarter of 2026, and the tactics inside that number have shifted specifically to defeat automated scanning.

QR code phishing is one example. Instead of putting a malicious link in the email body where a filter can scan it, attackers embed the link inside a QR code, often within a PDF attachment. A person scans it with their phone, which sits entirely outside the company's monitored network. Microsoft found that QR phishing volume grew by 146% in the first quarter of 2026, with most of it delivered via PDFs. CAPTCHA-gated phishing pages follow a similar logic. The page shows a human-verification screen before revealing the actual credential-harvesting form, which blocks automated security crawlers from ever seeing the malicious content. Instead of trying to sneak past employees, attackers are aiming for your scanning tools and increasingly succeeding.

Credential Theft Turns One Bad Click Into a Long-Term Problem

A firewall can't stop an employee from typing their real password into a fake login page. Once that happens, the attacker doesn't need to breach anything else. They log in like the employee would, often keeping the account under observation for days or weeks before acting. Phishing-as-a-service platforms have made this kind of attack available to criminals with limited technical skill. These kits impersonate common sign-in pages and are built specifically to defeat multifactor authentication that isn't phishing-resistant, intercepting the session after a real MFA prompt is completed rather than trying to guess a password.

This matters because MFA gets sold to small business owners as a complete solution, and it isn't one on its own. Standard MFA, the kind that sends a text code or an app push notification, can still be intercepted by a well-built fake login page sitting between the employee and the real service. Phishing-resistant MFA, using hardware security keys or platform-based authentication, closes that gap. Microsoft's research shows MFA blocks more than 99% of account-compromise attacks, but that figure mostly reflects automated password attacks. Against a live fake login page, standard SMS or push MFA can still be intercepted, while phishing-resistant methods cannot.

Why the Filter Alone Was Never Going to Be Enough

Native spam filters built into email platforms like Microsoft 365 or Google Workspace catch a large volume of obvious junk mail. What they consistently miss is anything that relies on impersonation rather than malicious code: a spoofed executive's request, a compromised vendor account sending real invoices with changed bank details, a lookalike domain one letter removed from the real one. None of that trips a virus scanner, because none of it is a virus.

This is where DMARC, SPF, and DKIM matter. These are authentication protocols that verify whether an email actually came from the domain it claims to be from. They exist specifically to catch spoofing that content filters cannot. Analysis of the FBI's 2025 data found that BEC, phishing, and government impersonation combined for over $4 billion in losses tied directly to attack types these authentication protocols are designed to prevent. Many small businesses never configure them correctly, or configure them once and never monitor whether they're still working as the company adds new marketing tools and vendors that send email on its behalf.

The Human Layer Is the Actual Target

CISA has found that 84% of employees who receive a malicious email interact with it within ten minutes of it landing in their inbox. That's not a training failure so much as a design problem in how these attacks are built. They arrive with urgency baked in: an overdue invoice, a CEO who needs a gift card purchased before a flight, a vendor whose bank account "changed" right before a scheduled payment. The person reading the email is under time pressure and has no reason to suspect a message that appears routine.

Firewalls and spam filters have no visibility into that moment of decision-making. A layered approach closes the gap: authentication protocols that detect spoofed domains, phishing-resistant MFA that limits what a stolen password can do, ongoing awareness training that keeps pace with new tactics like QR phishing, and a verification process for any payment or account change that never relies on email alone. A simple rule, such as confirming wire transfer changes by phone using a known number rather than one provided in the email, would have stopped a large share of last year's BEC losses.

Where Managed Cybersecurity Services Fit In

Most small businesses don't have a security team monitoring authentication logs, updating DMARC policies, or tracking which phishing kit is trending this quarter. That's the actual value managed cybersecurity services provide: continuous monitoring and response that a firewall was never built to deliver on its own. A managed provider configures and maintains email authentication correctly, deploys phishing-resistant MFA across the business, and runs ongoing simulated phishing tests. Employees build real pattern recognition and watch for account behavior that signals a compromise is already in progress, such as a sudden inbox rule that auto-forwards messages to an external address.

Email security for small business should be a set of practices that assume the firewall will let some things through (because it will) and that build the next layer of defense around the people and processes that actually make the final call on a wire transfer or password reset.

In our 16 years supporting small businesses, we know one thing to be true: the businesses getting hit the hardest are the ones that believe a firewall alone was covering more ground than it was designed to cover. At PK Tech, we maintain AICPA's SOC 2 Type II attestation, verified through an independent third-party audit of our security and privacy controls.

If your business is ready to address email security threats, contact us to schedule a call with our team.