DNS Filtering & Monitoring
Page EnquiryWhat Makes LoughTec’s DNS Filtering Different
Most DNS filtering tools work at the router or network level, meaning they only protect devices while they're in the office. The solution we deploy is device-based, so protection travels with your staff. A laptop working from home, a coffee shop, or a hotel room is just as protected as one sitting in your office, with no changes to your router, network infrastructure, or existing DNS configuration. There's no risk of breaking your network, VPNs, or Active Directory. It installs quietly in the background and just works.
Core Features
-
Device-Level Filtering
Threats are assessed and blocked at the endpoint itself, before a connection is ever made, not at the network edge. This is the critical difference for remote and hybrid workers. -
Full URL & IP Address Filtering
Many phishing attempts bypass traditional DNS protection by using raw IP addresses rather than domain names in malicious links. Our solution checks and blocks suspicious URLs and IP addresses in the browser before any connection is established. -
User Behaviour Analytics & Reporting
Beyond simply blocking threats, the platform provides visibility into web traffic and user activity across your devices, including full URL-level detail, without interfering with legitimate work. This means we can identify risky behaviour patterns, spot unauthorised applications or cloud services staff are using without IT knowledge and produce clear reports showing exactly what threats are being blocked on your behalf. -
Geo IP & Network Filtering
Traffic originating from high-risk countries or suspicious IP ranges can be blocked outright, a practical layer of defence against foreign threat actors. -
Zero-Trust Device Isolation
If a device is suspected of being compromised, it can be isolated instantly from the DNS management portal at the click of a button. Isolation seals off all traffic in and out of that machine, so an infection can't spread across your network while it's investigated and cleaned up.
Why Implement It, The Risk & Business Case
- DNS is the most attacked layer of the internet. Around 79% of cyberattacks use DNS as part of their chain, phishing, malware delivery, ransomware callbacks, and command-and-control traffic all rely on it. DNS filtering directly addresses the most common attack vector in use today.
- Your perimeter is no longer your office. Every device your team uses outside the building at home, travelling, on client sites is a potential entry point. DNS filtering closes that gap without additional complexity or infrastructure cost.
- Compliance and audit readiness. The reporting built into this solution gives you a documented, auditable log of threat activity and filtering decisions directly useful for ISO 27001 evidence gathering, cyber insurance renewals, and demonstrating due diligence to clients or regulators. You have a clear answer when asked "what controls do you have in place?"
- Shadow IT and AI visibility. Many breaches begin with an employee using an unauthorised cloud tool that IT doesn't know about. DNS filtering makes those tools visible, so we can assess whether they introduce risk and ensure your environment stays within compliance boundaries.
- Incident containment. If a device is compromised, automatic isolation limits the blast radius stopping an infection spreading across your network before remediation begins.
Web Application Control & Acceptable Use
DNS filtering also gives you granular control over which websites, web applications, and entire categories of online content can be accessed on your business devices. This goes well beyond simply blocking known malware. We can restrict or completely block access to social media platforms, gambling sites, adult content, and recruitment portals, reducing distraction, protecting your organisation from reputational risk, and ensuring company devices are used appropriately during working hours. Increasingly, this also extends to the fast-growing landscape of AI tools, platforms like consumer AI chatbots, image generators, and AI-powered productivity apps like ChatGPT, Claude, GROK, Perplexity etc that staff may be using without IT or management awareness.
This matters because employees inputting sensitive business data, client information, or proprietary content into unauthorised AI platforms represents a genuine data governance and confidentiality risk, one that most businesses haven't yet formally addressed. Through DNS filtering we can identify exactly which AI tools are being accessed across your estate, block specific platforms outright, or whitelist only the approved tools your business has assessed and sanctioned. Combined with category-level blocking for content that has no legitimate business purpose, this gives you a clear, enforceable acceptable use policy that is actively monitored and reported on, not just a document sitting in a drawer.
What It Means in Practice
|
Risk |
Without DNS Filtering |
With DNS Filtering |
|---|---|---|
|
Staff clicks phishing link |
Connection made, credentials stolen |
Blocked before connection |
|
Remote worker on home network |
Unprotected |
Fully covered |
|
Unauthorised SaaS apps in use |
Invisible to IT |
Flagged and reportable |
|
Ransomware callback traffic |
Unrestricted |
DNS request blocked |
|
Evidence for insurance / audit |
Manual, patchy |
Automated and logged |
DNS filtering is one of the highest-impact, lowest-disruption additions we can make to your security stack. It sits quietly in the background, protecting your team wherever they work, giving us the visibility to act fast when something happens, and giving you the reporting to demonstrate your security posture to insurers, clients, and auditors.
It's not a replacement for your other controls, it's the layer that catches what everything else doesn't see before the damage is done.
Frequently Asked Questions
Everything your team needs to know about how DNS filtering works and why it matters for your business.
Every time someone on your team visits a website or clicks a link, their device sends a DNS request, essentially asking the internet where that address leads. DNS filtering intercepts that request before any connection is made and checks it against a continuously updated database of known threats. If the destination is malicious, the request is blocked instantly and silently. If it is legitimate, the user reaches it without interruption. This happens at the device level, meaning protection is always active regardless of where your staff are working.
Around 79% of cyberattacks use DNS as part of their chain including phishing, ransomware, and malware delivery. SMEs are increasingly targeted precisely because attackers assume their defences are lighter than those of larger organisations. DNS filtering is one of the most cost-effective controls available, it stops threats before they reach your devices or your staff, requires no change to your existing infrastructure, and runs quietly in the background without affecting day-to-day operations.
Yes, and this is one of its most important advantages. Traditional network-level DNS filtering only protects devices connected to your office network, leaving remote and hybrid workers exposed. The device-based approach we deploy travels with the device itself, so a laptop working from a home broadband connection, a hotel, or a client site has exactly the same level of protection as one sitting in your office. No VPN dependency, no configuration changes per location.
Yes. Phishing sites and ransomware delivery infrastructure both rely on DNS to function. When a staff member clicks a malicious link in an email, DNS filtering checks the destination before any connection is made and blocks it if it is flagged as harmful. The solution also filters full URLs and raw IP addresses, closing a common gap where attackers bypass domain-based filtering by embedding IP addresses directly into phishing links. Ransomware is also prevented from making the callback connections it needs to activate and spread, even after a device has been compromised.
Shadow IT refers to software, cloud services, and applications that employees use without the knowledge or approval of the IT team. Common examples include personal file sharing services, unauthorised communication tools, and consumer AI platforms. These introduce real risk, data may be stored outside your control, compliance obligations may be breached, and security vulnerabilities may go undetected. DNS filtering gives us full visibility into which services are being accessed across your estate, so we can identify unsanctioned tools, assess the risk they carry, and take action where necessary.
Yes. Consumer AI tools — including AI chatbots, image generators, and AI-powered productivity platforms — represent a growing and largely unmanaged data risk for businesses. When employees input client data, commercially sensitive information, or confidential business content into these platforms, that data is processed and potentially stored by third parties outside your control. DNS filtering lets us identify all AI tools being accessed across your devices, block specific platforms that have not been assessed and approved, and whitelist only the tools your business has formally sanctioned. This turns an informal problem into a managed, auditable policy.
Yes. DNS filtering gives you granular control over which categories of website and web application can be accessed on your business devices. You can restrict or block access to social media platforms, gambling sites, adult content, recruitment portals, gaming platforms, and any other category that falls outside your acceptable use policy. Rules can be applied across all devices at once, adjusted by user group, or amended quickly when business needs change. This supports both productivity and compliance objectives, and the activity is logged and reportable.
DNS filtering contributes directly to both. For ISO 27001, it provides documented evidence of technical controls around malware protection, access control, and monitoring, all areas assessors look at closely. For cyber insurance, insurers are increasingly asking applicants to demonstrate active technical controls rather than simply declare that policies exist. DNS filtering gives you an auditable log of blocked threats, filtering decisions, and user activity that you can present as tangible evidence. It also reduces your actual risk profile, which can positively affect premium assessments at renewal.
No. The solution we deploy is device-based and requires no changes to your DNS settings, routers, or network infrastructure. It does not interfere with VPNs, Active Directory, or custom DNS configurations. It installs as a lightweight agent on your devices and operates silently in the background. Deployment is straightforward, typically taking well under an hour per site, and we manage it on your behalf. Your team will not notice it is there unless a threat is blocked.
The platform generates detailed reports covering threats blocked, websites accessed, user activity patterns, and any shadow IT or unauthorised applications identified across your devices. These reports are available to us in real time and we share them with you in a format that is meaningful to your business, not a list of technical alerts, but a clear picture of what is happening across your estate. You will have documented evidence that your defences are active and working, which is increasingly important for board-level governance, insurance renewals, and client due diligence requests.

