You need the basics: protect perimeter (firewall), protect endpoint (good av with IA) and a good antispam with sandbox.
I suggest in the firewall make security zone's and only permit specific traffic, ports, protocols, etc.
Take the FortiGate 40F with UTM protection (600 Mbps Threat Protection), easy management and low cost for your requirement. If you need load balance WAN links choose the 60F because it has more physical ports and 700 Mbps Threat Protection.
Hello,
I think Fortigate with Soc3 (60E,80E,100E) will perform better due the higher vpn throughput.
If you plan to add ips, av and so on I would suggest to move to FGT200E or NSA2650 at minimum