NET / NET-07
DNS security and protective resolution filtering
Protect the service that resolves domain names and control destinations resolved by devices. The service addresses internal DNS availability and detection or blocking of domains considered dangerous.

WHEN IT HELPS
A focused response
to a defined need.
Uncontrolled DNS, endpoints using external resolvers, suspicious-communication alerts or critical dependence on poorly documented internal DNS.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Resolver architecture
- internal/external separation
- change control
- filtering
- proportionate logging
- administrative access
- continuity
- handling encrypted DNS use
Deliverables
- DNS architecture
- resolution policies
- configurations
- exception list
- incident procedures
- resolution and failover tests
- sensitive-zone documentation
Acceptance evidence
Business resolution is validated; an agreed test domain is blocked; administration is protected; continuity is tested; known bypasses are documented with agreed measures.
DELIVERY
How the work is structured.
Approach
Map traffic; design and size; pilot; migrate gradually with rollback; test and document operations.
Prerequisites & responsibilities
Customer: networking, applications, carriers, change windows and business acceptance. Provider: design, migration and tests. Third-party access and TLS inspection require suitable approvals.
Scope factors
Sites, actual inspected throughput, traffic, rules, remote users, availability and integrations. Hardware, security subscriptions and recurring operations are separate.
Questions to clarify
Who administers zones and domains? Can endpoints bypass resolvers? Which services fail during a DNS outage?
IMPORTANT BOUNDARIES
DNS filtering does not see every exchange and does not replace EDR or firewalls. Encrypted DNS and direct IP access can change its coverage.
Changes preserve essential services and recovery paths. Sizing, licensing and acceptance tests reflect the features that will actually be enabled.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A company has different DNS configurations across sites. Project: standardise resolvers and apply common filtering. Target outcome: consistent behaviour and resolution incidents that support can diagnose.
Scenario 02
An organisation loses services when its primary DNS fails. Project: review redundancy, backups and change controls. Target outcome: verified recovery; non-redundant dependencies remain identified as risks requiring treatment.
Technology and reference context
Examples: secured internal resolvers and protective DNS services; firewall integration depends on subscriptions and architecture.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
