NetBEUI can't be routed so cannot be exposed to the internet. It was great for really small networks on a single broadcast domain as it required no configuration. You just turned it on and machines could communicate.

However, anyone using TCP/IP should be configuring their firewall with a default block any/any rule, then justifying any exceptions. In any org I have worked in, you would normally only expose ports to machines in a DMZ to the internet. You would need an extremely strong justification to open any ports to the internal network and have to demonstrate that there was no alternative. Anyone suggesting opening SMB to the internal network would probably be told to go sit in the corner with a dunce cap on their head.

