What these controls still do well
Antivirus and firewalls are not obsolete. Security software can stop known or suspicious code on a device, while a firewall can filter network traffic and restrict exposed services. Both belong in a basic security program. The mistake is expecting them to cover activity they cannot see.
- Detect or block known and suspicious code running on a protected device.
- Filter inbound and outbound network connections according to policy.
- Reduce exposure to common malware, scanning, and unwanted services.
- Provide one source of evidence when a device or network connection is investigated.
Where their visibility ends
Many damaging actions now use a valid account or an approved tool. No malicious file has to run, and the activity may never cross the office network.
- A stolen password or session used to sign in to Microsoft 365 or Google Workspace.
- Business email compromise that relies on impersonation or a changed payment instruction.
- Inbox rules, forwarding, OAuth grants, and sharing changes made through legitimate features.
- Built-in administrative and remote-management tools used for unauthorized activity.
- Cloud data accessed from an unmanaged device outside the office network.
Build around the account, device, and data
Microsoft 365, Google Workspace, and other cloud applications are reached directly from homes, client sites, and mobile devices. An attacker using a stolen session can reach the same email and files as the user without sending recognizable malware through the office firewall.
Device activity creates a similar problem. An attacker can use PowerShell, remote administration, or other built-in tools that also have legitimate uses. A useful response depends on context: which account ran the action, on which device, after which sign-in, and what happened next.
This is why identity, email, endpoint, application, and cloud audit records need to be reviewed together. Protected backups and a tested response path handle the part no preventive tool can guarantee: recovery after a control misses something.
A practical baseline
Test the gaps, not the product list
A few plain questions expose the gaps. If a partner account is compromised, who sees the risky sign-in, forwarding rule, file download, or suspicious sent message? If a laptop is infected, who can isolate it and investigate? If cloud data is encrypted or deleted, can it be restored without relying on the same compromised administrator account?
Then check ownership. A product may support strong controls, but that does not mean someone reviews its alerts, tunes its policies, preserves evidence, or responds after hours. Write down who owns each action and how that person is reached.
The right baseline depends on the sensitivity of the data, the access people hold, and the cost of an interruption. Headcount alone does not answer those questions. Strong authentication, supported and monitored devices, safer email, recoverable data, and a response owner form the baseline. Additional controls should follow the actual risk.

