Skip to content
Offices

Protective DNS: a threat layer behind the office firewall

Office networks carry managed laptops, personal phones and visitors in the same building. Shield blocks command-and-control callbacks at the lookup, flags new threats early and keeps staff and guest networks on their own rules, without one more agent to push.

Protect a network free for 30 days

What is at stake

Managed and unmanaged devices in one building

  • BYOD and visitors

    Devices no agent will ever reach still share the building's WiFi.
  • Devices calling home

    An infected device reaching its command-and-control server is a breach in progress.
  • Ageing firewalls

    Firmware falls behind. A DNS layer closes the gap.

How Shield fits

Staff and guests on their own rules

  • Staff on EAP-TLS with MDMThreat defence first, with staff allow and block lists.
  • Guest WiFiFamily-safe categories and ad blocking, so pages load up to 500% faster.
  • Tenants and IoTxPSK networks on their own VLANs and policies.
  • ReportingThreat analysis and blocked URLs, by network.

Need logs in your SIEM, or Shield behind an existing firewall and NAC? Talk it through with a Shield expert.

Proof

Earlier warning, lighter networks

10 days
earlier warning of new threats than standard blocklists
62%
fewer DNS queries with ads stripped
  • ISO 27001certified, alongside GDPR, CCPA and Cyber Essentials

FAQ

Questions we hear from teams like yours

We already have a firewall. Why add Shield?

Shield is a layer behind it. It stops the lookup before a connection starts, blocks command-and-control callbacks and covers devices an endpoint agent never touches.

Can staff and guests have different rules?

Yes. Each SSID and VLAN carries its own policy.

Other industries

  • Hospitality

    Family-safe, faster guest WiFi with protective DNS for pubs, hotels and venues

    Family-safe guest WiFi and faster pages for pubs, hotels and family venues.
  • Education and student accommodation

    Safeguarding on every student and resident network

    Safeguarding per network and per VLAN for schools, campuses and student accommodation.
  • Healthcare

    Around 241,000 threats a week, stopped on hospital guest WiFi

    Threat defence on patient and visitor WiFi, proven at St George's Healthcare NHS Trust.

Decide what your WiFi reaches, free for 30 days

Tell us which networks you run and who is on them. We map a policy to each one: guests, staff, students, residents and paid tiers. Then point one network at Shield and see what it stops for 30 days, before you pay anything. Running change control? We plan a pilot on one SSID with your team instead. No hardware, no agents on devices.

  1. We map your networksA Purple expert maps your networks, your venues and the people on each, and answers your questions on bypass, outages, data handling and integrations.
  2. You get a policy for each oneGuests, staff, students, residents and paid tiers, each with the policy it needs.
  3. You prove it, then get your tailored quote30 days free on one network, or a pilot on one SSID planned with your team, then Shield priced standalone or as an add-on to your Access plan.

Your policy map

Tell us your networks. We map a policy to each one.

A Purple expert comes back with a policy for every SSID you run, from the team that has run content filtering on WiFi since 2012 and runs WiFi for 80,000+ venues in 90 countries.