Use DNS Filtering Services
Almost everything malicious has to make a phone call. A phishing link has to resolve to a web address. Malware has to reach back to its operator for instructions. Ransomware often checks in before it starts encrypting. Every one of those steps begins the same way, by looking up a domain name. DNS filtering sits at that lookup and refuses to connect to destinations known to be dangerous, which means a surprising number of attacks fail at the very first step, before anything is ever downloaded or opened.
For how little it costs and how little friction it adds, this is one of the highest-leverage controls in all of IG1. It works quietly in the background and stops trouble a step earlier than almost anything else you have.
What this control actually says (in plain English)
Here’s the translation: use a service that blocks your computers from reaching known-bad web addresses at the moment they try to look them up.
Now the official version. Control 9.2 says you should use DNS filtering services on your enterprise assets to block access to known malicious domains.
Every device already performs these domain lookups constantly. This control simply routes them through a service that knows which destinations to refuse.
Why business leaders should care
The appeal here is leverage. DNS filtering doesn’t try to detect a clever attack in progress. It cuts off the connection to the bad destination before the attack can really begin. When an employee clicks a convincing phishing link, filtering can stop the malicious page from ever loading. When something does slip onto a machine, filtering can block it from reaching back out to its operator, which often stops the damage before it spreads. One inexpensive control quietly interrupts several very different attacks, and your people rarely even notice it’s there.
It also fits the reality that your business no longer lives inside one building. When I wrote about firewalls and a default-deny posture in Why “Default Closed” Is a Business Advantage, the point was that protection can’t depend on a single perimeter anymore, because work happens from homes, airports, and client sites. Modern DNS filtering follows the device wherever it goes, so a laptop is just as protected on hotel Wi-Fi as it is at the office. It’s the same instinct, applied to the connections your systems make out to the internet.
What “good” looks like
This is one of the faster controls to stand up, and the value shows up almost immediately. Here’s the practical path.
- Turn on a reputable filtering service everywhere. Use a well-regarded DNS filtering or protective DNS service, and apply it to every device, not just the ones sitting on the office network.
- Cover roaming and remote devices. Make sure laptops stay protected off-network, since that’s often where the riskiest browsing happens. This is where a client-based or cloud-delivered service earns its value.
- Block by category, not just known-bad. Beyond confirmed malicious domains, consider blocking high-risk categories that have no business purpose, which shrinks your exposure further.
- Watch what it catches. Review the blocks. A spike in attempts to reach malicious domains is an early warning worth paying attention to, not just a number.
The audit and defensibility angle
DNS filtering gives you something clean to point to: a control that actively blocks connections to known-malicious destinations across your fleet, with a log of what it stopped. That’s easy to explain to an auditor or an insurer, and the record of blocked attempts is useful evidence that your defenses are doing real work. It also pairs naturally with the broader secure-access approach many organizations are moving toward, where filtering, identity, and access controls travel with the user rather than living at a single gateway.
Most attacks have to reach out to succeed, and DNS filtering hangs up that call before it connects. For a control that costs little and bothers your people almost not at all, it stops a genuinely wide range of threats a full step earlier than anything else in your stack. Turn it on everywhere, make it follow your devices, and let it quietly do its work.






