A key feature most likely missing from your edge router/firewall is something in place to protect
the rest of your LAN and the world from a rogue host inside your network.
A decent software firewall on workstations can if properly configured help when (not if but when) a dork inside your network opens the wrong attachment from the wrong person. Without a proper IDS config, properly communicated and enforced usage policies, user training, and locked down systems, you are avoiding many aspects just as important as hiding your users behind a DLINK.

Egress safeguards being too often overlooked are a huge problem on the net today.

So use your software firewalls if you can. I would be just as concerned about saving the world from your LAN than saving your LAN from the world...