If you do not have the security enhancements of a DMZ, you or your organisation should NOT be connected to an untrusted network – especially the Internet. Not having an Internet connection these days is inconceivable and therefore, it is not a case of should have, but more a case of must have when it comes to implementing a DMZ security zone.
"Network security does not stop at the perimeter firewall!"
Having a well configured and maintained firewall is just the beginning of a sound network security model. The firewall is your front-line defence against unauthorised access to your network and resources but by no means should it be the last defense.
The firewall is not always responsible for inspecting packet payloads especially if the payload is encrypted. By adding a DMZ security zone with properly configured reverse proxy and bridging services, you are adding an additional layer of security between your perimeter firewall and your trusted network making it that much more complex for a potential attacker to reach your critical information and services.