Pulse Technology Blog

MFA, EDR, Firewalls and More: Understanding Your Cybersecurity Stack

Written by Vince Mazza | September 21, 2026

Key Takeaways

  • A cybersecurity stack should protect accounts, devices, networks, applications, and data.
  • MFA, EDR, and firewalls address different risks and work best as part of a layered security approach.
  • Backups, software updates, monitoring, and response planning are just as important as preventive security tools.
  • Security tools need regular configuration, updates, monitoring, and testing.
  • Review the cybersecurity stack as the business adds devices, applications, and other technology.
  • Clear responsibility for reviewing alerts and responding to threats helps prevent gaps between security tools.

A cybersecurity stack is the collection of security tools, services, controls, and practices a business uses to address risks such as stolen passwords, phishing, malicious software, unpatched vulnerabilities, and data loss.

If one protection fails or is bypassed, another layer may still detect the activity, limit how far it spreads, or help the business recover.

Here are eight layers a modern cybersecurity stack should include.

1. Identity and Access Protection

Identity and access protection helps keep business accounts out of the wrong hands and ensures each person can access only what they need.

MFA adds another step after someone enters a password. That might mean approving a request in an authentication app, using a security key or passkey, or confirming a biometric identifier. If an attacker steals or guesses a password, the additional check can stop them from using it on its own.

MFA is especially important for email, Microsoft 365, remote access, cloud applications, financial systems, and administrator accounts. It should cover all accounts that could give an attacker access to important systems or information. Protecting email will not help, for example, if a cloud application can still be accessed with only a password.

A password manager makes it easier to use a different password for every account. That way, one stolen password is less likely to open the door to several systems.

It is also important to look at what happens after someone signs in. People should have access to what they need for their roles, but not systems or information they do not use. Shared and inactive accounts, unnecessary administrator access, and old permissions can all create openings that are easy to overlook.

2. Device Protection

Laptops, desktops, and servers all need protection, whether they are used in the office or somewhere else.

EDR, or endpoint detection and response, monitors these devices for activity that doesn't look right. It might spot a program making unexpected changes to files, an account behaving differently than usual, or a computer trying to connect to systems it normally would not use.

When EDR finds something suspicious, it can block the activity, quarantine a file, disconnect the device from the network, or alert someone to investigate.

This goes further than traditional antivirus, which mainly looks for known malicious files. An attacker may use legitimate software already installed on a computer or sign in with a stolen account, so there may be no obvious malware to find.

Device protection also includes encrypting sensitive data, controlling which applications can be installed, and maintaining an up-to-date list of devices that can access business systems. These safeguards should cover remote computers as well as office devices.

3. Network Protection

A firewall acts as a gatekeeper for your network, allowing approved traffic through and blocking connections that should not be there.

Business-grade firewalls can do more than screen incoming and outgoing traffic. They may also block risky websites, look for malicious content, flag suspicious activity, and provide a secure way to connect remotely.

Not every device needs access to every part of the network. Guest Wi-Fi, printers, security cameras, and production equipment can be kept separate from computers and servers containing confidential information. If one device is compromised, that separation can make it harder for an attacker to reach other systems.

The office firewall does not cover everything, though. People may connect to cloud applications and business data from home or while traveling. Secure remote access, properly protected devices, and strong login controls help protect those connections outside the office.

4. Email and Application Protection

Email gives attackers plenty of ways to reach a business. A message might contain a malicious attachment, lead to a fake login page, or appear to come from an executive or supplier asking for a payment or account change.

Email security tools scan messages, links, and attachments for signs of trouble and block many before they reach an inbox. Some can also spot messages that imitate a familiar name or email address.

No tool will catch every convincing message, especially when there is no suspicious link or attachment. People need to know how to verify an unusual request and where to report a message that does not look right.

Cloud applications need the same attention. A business should know which applications people use, who has access, and what information they store. When someone adds an application without reviewing its security, it can create a gap the business doesn't know exists.

5. Patch and Vulnerability Management

Firewalls and EDR can help stop or detect an attack, but you should fix known security weaknesses before attackers can use them.

Software updates often repair these weaknesses. Patch management tracks which devices and applications need updates, helps prioritize the most serious issues, and confirms that patches were installed properly.

Vulnerability scanning looks for problems such as missing updates, unsupported software, unsafe settings, and systems exposed to the internet. These checks should cover servers, firewalls, wireless equipment, printers, and other connected devices, not only computers.

Start by identifying which devices and applications the business uses. A forgotten device or application can go unpatched for months because no one realizes it is still connected or in use.

6. Data Protection and Recovery

Business data needs protection wherever it is stored, shared, or accessed.

Encryption makes information unreadable to anyone without permission to view it. This can protect sensitive data if a laptop is lost or stolen or if someone gains unauthorized access. Clear rules for file sharing, cloud storage, and removable devices can also help keep information out of the wrong hands.

Backups give the business a way to recover when files are deleted, corrupted, or encrypted by ransomware. Keep at least one backup copy separate from other systems or make it immutable, meaning it cannot be changed or deleted. Otherwise, an attacker who reaches the network may be able to damage the backups too.

A backup is only helpful if it works when you need it. Regular restoration tests confirm that the right information is being saved and that important systems and files can be recovered.

7. Security Awareness

Suspicious requests do not arrive only by email. They can also come through text messages, phone calls, collaboration platforms, and social media. Training helps people recognize phishing, impersonation, unusual file-sharing requests, and other attempts to get around the company’s normal procedures.

The most useful training reflects the situations people may encounter and provides regular reminders. It should also make the next step clear: how to report something suspicious and what to do after clicking a link or sharing information by mistake.

The sooner someone reports a concern, the sooner the IT or security team can check the account, remove a malicious message, or warn others who may have received it.

8. Monitoring and Response

Security alerts only help if someone is paying attention to them. When a firewall, EDR platform, or other security tool spots something unusual, someone needs to decide whether it is a real threat and what should happen next.

A single alert may not look serious. But when it appears alongside an unusual login, a blocked email, or unexpected activity on a device, it may be part of a larger attack.

Businesses with an internal security team may monitor and investigate alerts themselves. Others use managed detection and response, or MDR, which provides security specialists to watch for suspicious activity, investigate alerts, and help contain a threat.

The business also needs a response plan. Who can disconnect an affected device? Who contacts leadership? When should the cyber insurer, legal counsel, law enforcement, or an outside security specialist be called? Deciding this ahead of time can prevent confusion when every minute matters.

The potential cost makes that preparation important. IBM’s 2025 Cost of a Data Breach Report placed the average cost of a U.S. data breach at $10.22 million. Costs vary from business to business, but the point is clear: keeping attackers out matters, and so does being ready to respond if they get in.

Do the Layers in Your Stack Work Together?

Having a tool for each layer doesn't necessarily mean everything is covered. A security product may not be configured correctly, an alert may go unnoticed, or a device or account may be left out.

As you review your cybersecurity stack, consider these questions:

  • Is MFA required for every important account?
  • Does EDR cover all business-owned computers and servers?
  • How quickly are serious software vulnerabilities patched?
  • Who reviews the security settings for email and cloud applications?
  • Are backups kept separate and tested regularly?
  • Who monitors alerts and responds when something looks wrong?
  • If an issue involves more than one provider, who takes the lead?

These questions can uncover missing protection, but they may also reveal tools that overlap, features the business pays for but doesn't use, or security responsibilities no one realized were unassigned.

Take a Closer Look at Your Cybersecurity Stack

More security tools don't always mean better protection. What matters is whether your tools cover your accounts, devices, networks, applications, and data, and whether someone knows what to do when an alert comes in.

Pulse Technology can review how your business currently protects its accounts, devices, network, applications, and data. The review can identify unprotected accounts or devices, missing security controls, unmonitored alerts, and unclear response responsibilities. If you're unsure where the gaps are, contact Pulse to schedule a cybersecurity assessment.

Frequently Asked Questions

How can I tell if there are gaps in my cybersecurity stack?

Start by checking whether every important account, device, application, and source of business data is covered by the appropriate security tools. Common gaps include accounts without MFA, computers not monitored by EDR, software that no longer receives updates, backups that haven't been tested, and security alerts that no one is responsible for reviewing.

Can cybersecurity tools from different vendors work together?

Yes, but compatibility and responsibility need to be clear. Businesses should know whether tools share useful information, whether any systems are left uncovered, and who investigates an issue that touches more than one platform.

How often should a cybersecurity stack be reviewed?

A full review should generally take place at least once a year and after a major business or technology change. Check alerts, backups, software updates, and account access much more frequently.