Coleman Technologies Blog

Blogs on IT Support and Cybersecurity for Small Business

Insights on cybersecurity, AI, and IT strategy to help business leaders reduce risk, improve performance, and make better technology decisions.

Web and DNS Filtering for Abbotsford Small Businesses Catches the Mistake Your Team Already Made

Untitled-design-4

Somebody on your team will click a bad link this year, and no amount of training changes that. Web and DNS filtering for Abbotsford small businesses exists for the half second after the click, when a browser asks where to go and something decides whether to answer.

The Lookup Nobody Sees

Every visit to a website starts with a request for directions. The Domain Name System translates a name people can read into an address a machine can use. The Canadian Centre for Cyber Security describes DNS as the address book for the internet, and notes that almost everything an organization does online depends on it.

That request is the moment of leverage. A filtering service checks the requested domain against threat intelligence before any connection opens. When the domain is known to host phishing pages or malware, no address comes back and the page never loads.

Your employee sees a block notice instead of a convincing fake login screen. Nothing downloads. No credentials get typed into a form built to harvest them.

The control is unglamorous, which is part of why it gets skipped. There is no dramatic alert and no story to tell afterward. The whole point is that nothing happened.

That also makes it hard to justify in a budget meeting. A firewall is a box somebody can point at. Filtering is a setting, a subscription, and a policy document, and its output is an absence of events.

Attackers Work Through the Address Book

The Cyber Centre reports that industry estimates place between 80 and 90 percent of cyber attacks as leveraging DNS in some way. That figure sounds inflated until you look at how ordinary the mechanism is.

A malicious email needs a destination. Malware needs to reach its operator. A fake login portal needs somewhere to live.

Each of those steps involves a name that has to be resolved into an address first. Interrupt the resolution and you interrupt the step.

This is also why filtering catches things that arrive by routes other than email. A link pasted into a chat message behaves the same way. So does a search result, a QR code on a printed invoice, and a bookmark saved months ago to a site that has since been taken over. Web and DNS filtering for Abbotsford small businesses sits below all of those channels rather than guarding any one of them.

The Canadian data supports the same logic from a different angle. Statistics Canada's most recent Survey of Cyber Security and Cybercrime found that about one in six businesses, or 16 percent, were impacted by cyber security incidents in 2023. What impacted them tells you more than the headline number.

  • Scams and fraud were the most common method, affecting 50 percent of impacted businesses, up six percentage points from 2021.
  • Identity theft climbed fastest, reaching 31 percent of impacted businesses after an eleven point jump.
  • Ransomware affected 13 percent of impacted businesses, up from 11 percent two years earlier.
  • Just 22 percent of businesses provided formal cyber security training to employees outside their IT function.

Read those together and a pattern surfaces. The dominant attack methods depend on persuading a person to do something, and most Canadian businesses are not training the people being persuaded.

Where Awareness Training Runs Out

Training is worth doing, and the businesses that skip it are worse off. It is also the control most dependent on one person staying alert at exactly the wrong moment.

People are tired at 4:30 on a Friday. A message arrives from a supplier you genuinely use, referencing an order you are genuinely expecting. The domain is off by a single character, and the logo is correct because it was copied from the real site an hour ago.

Asking someone to catch that while they are also doing their actual job is a thin margin to build a security posture on. It works most of the time. Most of the time is not the standard you want when the failure mode is a compromised mailbox.

Statistics Canada found that only 26 percent of businesses had written cyber security policies, and half reported having any cyber security employees, down from 61 percent in 2021. Most small organizations in the Fraser Valley are running on general awareness rather than a documented program, which puts a great deal of weight on individual judgment.

What a Filter Catches That People Miss

Web and DNS filtering for Abbotsford small businesses does not require anyone to notice anything. It applies the same judgment to every request, at every hour, on every device it covers.

  • Phishing pages hosted on domains registered days or even hours earlier
  • Malware attempting to reach its command and control server after landing on a machine
  • Legitimate sites that have been quietly compromised without the owner knowing
  • Typo domains that catch a mistyped bank, supplier, or software address
  • Unsanctioned file sharing and remote access tools staff install on their own initiative

The Cyber Centre's foundational guidance for small organizations lists protective DNS alongside antivirus software, VPNs, and firewalls. It sits in the baseline category rather than the advanced one, which is a useful signal for anyone deciding where to spend next.

The Laptop That Leaves the Building

Your office firewall protects traffic that passes through your office. That covers less of the working week than it did five years ago.

Staff take laptops home, out to job sites across the valley, and onto hotel Wi-Fi in another province. On those networks your firewall rules do not apply and your monitoring sees nothing at all. Statistics Canada found that 46 percent of businesses monitor their networks and business systems, making it the most common risk identification activity, but that monitoring stops at the edge of the network.

A filtering agent installed on the device travels with the device. The same policy applies in the boardroom, in a truck cab, and at a kitchen table in Clearbrook.

This is where filtering earns most of its value. Protective DNS also extends to phones and tablets, where conventional antivirus often cannot be installed at all. It holds up under a bring your own device arrangement, where the company does not control the hardware in the first place.

Why the Compliance Angle Is Not an Afterthought

Under PIPEDA, an organization that suffers a breach of security safeguards has to assess whether it creates a real risk of significant harm. If it does, the organization must report to the Privacy Commissioner and notify the individuals affected. Records of every breach have to be kept for two years regardless of that assessment, and the Privacy Commissioner is explicit that small businesses are covered.

A credential harvested through a fake login page is exactly that kind of event. Preventing the connection is considerably simpler than working through the assessment, the notification, and the client conversations that follow.

Insurers have noticed the same thing. Statistics Canada recorded cyber risk insurance uptake rising to 22 percent of businesses in 2023 from 16 percent in 2021, and applications increasingly ask what preventative controls are actually in place.

What Filtering Will Not Do

Honest limits are more useful than a feature list.

  • It does not inspect page contents, so a malicious file on a domain nobody has flagged will still resolve.
  • It does not stop traffic that avoids domain names entirely and connects straight to an address.
  • Browsers using encrypted DNS can route around a filter unless the deployment accounts for that.
  • It does not replace multi-factor authentication, patching, backups, or endpoint protection.

Filtering reduces how often a human mistake turns into an incident. It does not make mistakes impossible, and any provider claiming otherwise is selling something. Layers work precisely because each one fails differently.

Rolling It Out Without Breaking the Workday

Filtering earns a bad reputation when it is deployed as a blunt instrument. Block too much and staff find ways around it, usually on personal devices you cannot see. Block too little and it becomes decoration.

Category policy is where most of the internal debate happens. Newly registered domains, known malware hosts, and phishing infrastructure should be blocked without argument. Categories such as personal webmail, streaming, and file sharing depend entirely on how your business actually operates, and a distribution warehouse will land somewhere different from an accounting firm.

  • Start in monitoring mode and review real traffic for a week before enforcing anything.
  • Block security categories first, and treat productivity categories as a separate conversation.
  • Build an exception process staff can use in minutes rather than days.
  • Extend the agent to laptops and mobile devices instead of stopping at the office network.
  • Review block reports monthly, since they show what is being aimed at your people.

That final point gets overlooked most often. Block logs are a free source of intelligence about which staff are being targeted and what the current campaigns look like.

They also settle arguments. When somebody insists the filter is too aggressive, the report shows what was actually blocked and why, which turns a complaint into a five minute policy adjustment.

Fitting It Into a Layered Stack

Statistics Canada found that 47 percent of businesses without dedicated cyber security employees said they rely on consultants or contractors instead. For a great many small organizations in Abbotsford and the surrounding valley, that is simply the practical model, and filtering is among the easier layers to hand across.

The argument for adding it is not that it is impressive. It is that it does its work on an ordinary Tuesday, when somebody is distracted and the link looks entirely reasonable. Web and DNS filtering for Abbotsford small businesses is a quiet control, and the evidence it is working is a page that never loaded.

Sources:

  • Canadian Centre for Cyber Security, Protective Domain Name System (ITSAP.40.019)
  • Canadian Centre for Cyber Security, Foundational cyber security actions for small organizations (ITSAP.10.300)
  • Statistics Canada, The Daily: Impact of cybercrime on Canadian businesses, 2023 (Canadian Survey of Cyber Security and Cybercrime)
  • Office of the Privacy Commissioner of Canada, PIPEDA breach of security safeguards reporting requirements
Continue reading

How to Save a Website as an Application

How to Save a Website as an Application

If you feel like you have too many browser tabs open at any given time, then you'll be happy to know that you can sometimes save certain browser tabs as a standalone application on your device. This will give them their own icon and make accessing them much easier than constantly navigating to them through your web browser.

Continue reading

Browser Cookies Explained

Browser Cookies Explained

When someone mentions cookies, people start paying attention. Chocolate chip, oatmeal raisin, snickerdoodles… Browser? While Browser cookies aren’t the most scrumptious, they do need some attention. Nowadays, many websites you visit have a popup asking if they want to allow cookies for that site and knowing what you are agreeing to is important. In today’s blog, we will describe what cookies are, how they work, and why they can sometimes be better than cookies with chocolate chips. 

Continue reading

Fake Browser Updates Pose a Dangerous Threat

Fake Browser Updates Pose a Dangerous Threat

It’s important to keep the software on your computer updated. If your operating system or web browser or some other important application is out of date, it could lead to things not working properly while also leaving you susceptible to threats. However, hackers are disguising malware to look like important web browser updates.

Continue reading

Your (Far From Comprehensive) Guide to Google’s Secrets and Easter Eggs

Your (Far From Comprehensive) Guide to Google’s Secrets and Easter Eggs

Since its domain was first registered on September 15, 1997, Google has exploded from a relatively simple search engine to the massive assortment of platforms and services that fall under the Alphabet umbrella. That being said, most people tend to think of very specific aspects of Google’s Search function… like the amusing Easter Eggs that the platform has become somewhat famous for.

Continue reading

Tip of the Week: Sharing Web Pages Between Chrome and Android

Tip of the Week: Sharing Web Pages Between Chrome and Android

It probably isn’t hard to think of a time when you’ve stumbled across something that would be useful for work while you were doing some personal browsing. What if I told you there was an easy way to send a website to your browser to view later? Thanks to Google Chrome, this is the case.

Continue reading

Tip of the Week: Easily Close Browser Tabs

Tip of the Week: Easily Close Browser Tabs

It’s easy to open up far more tabs on your web browser than you need, especially when so many tools are cloud-based. If you find yourself in need of a quick way to close all other tabs besides a handful or so, we’ve got just the tip for you. You can close all open tabs to the right of your preferred window, or you can close all tabs outright.

Continue reading

Tip of the Week: Reopening Closed Chrome Tabs and Windows

Tip of the Week: Reopening Closed Chrome Tabs and Windows

How often does this scenario happen to you? You’re going about your workday and are being quite productive, when all of a sudden you close the wrong tab in your web browser, putting an end to your productivity. This isn’t crippling downtime or anything, but it’s an inconvenience that we know you can do without. Thankfully, modern web browsers let you reopen closed tabs or windows to get back to where you left off.

Continue reading

Watch Out for Malicious Browser Extensions

How Do These Threats Work?

These attacks work similarly to how a phishing attack or a spoofed email would, as a user is promised one thing but winds up receiving something very different. While a malicious application may perform the task it claims to, it also may redirect the user to a phishing website or ad (making the cybercriminal some money) or simply steal some of the user’s information, like their birthday or email address.

Continue reading

Chrome Adds Color Coded Tabs and We’re So Thankful

Adding More Organization Into Your Chrome Browser

Admit it, you have a tendency to use too many browser tabs. At any given time, you may have 5-10-20 browser tabs open. If you use more than one screen, it could be more. Way more. Most users use their Chrome browser for so much of your online life that you hardly pay attention. Then you wonder why your PC is running slow. The truth is people use a lot of browser tabs, and they are better off for it. 

Continue reading

Tip of the Week: Keyboard Shortcuts for Convenient Browsing

If you want to try them out as you read along, make sure you open a new browser window… we don’t want you leaving this page before you read all of them!

Jump to Address Bar: Ctrl+L

Let’s say that it’s the beginning of your day, so you are checking your email for the first time. Afterwards, you know that you need to go to a particular website. Windows offers a quick shortcut that selects and clears the address bar so you don’t have to even stop typing before you move along. To make the jump, simply press Ctrl+L.

Continue reading

Know Your Tech: Breadcrumbs

What is Breadcrumb Navigation?
As per the aforementioned fairy tale, breadcrumb navigation consists of a path leading home. In this case, home is the homepage. With breadcrumb navigation, you can more easily keep track of how you got to the current web page you’re on, as well as the path back to the home page. This path can typically be viewed at the top of the page. Each step includes a link that navigates back to a specific page.

Let’s say that you’re looking at a service page on a website. If the path you took leads back to the home page, you’ll see all of the pages in between in the breadcrumbs menu. For the sake of this example, let’s say the pages in between are the second menu item and the fifth menu item. It would look something like this:

Home > [Menu 2] > [Menu Item 5]

Since these breadcrumbs are links, you can click on any one of them to be brought back to that page. This lets you continue browsing with minimal chance of getting lost on the site trying to backtrack.

More Than Just Websites
You might notice that this navigation style is similar to the ones used in toolbars in file folders or files saved on your desktop. The reason is the same--it makes finding certain files easier at a later date. The location can also be shared with others who need to know where it is.

Breadcrumbs are typically meant for helping users with browsing and organization. Are there any other features out there you can think of that do the same thing? Let us know in the comments.

Continue reading

About Coleman Technologies

Coleman Technologies is a managed IT and cybersecurity partner for growing businesses that can’t afford downtime, breaches, or guesswork. For over 25 years, we’ve helped organizations across British Columbia run stable, secure, and scalable technology environments—backed by 24/7 support, enterprise-grade security, and clear accountability. We don’t just fix IT problems. We take ownership of them.

get a free quote

Understanding IT

Get the Knowledge You Need to Make IT Decisions

Technology is constantly evolving, and keeping up can feel overwhelming. Whether you want to understand cybersecurity threats, explore automation, or learn how regulations like PCI DSS impact your business, we’ve made it easy to access clear, straightforward insights on key IT topics.

Insights to Understanding IT

Contact Us

20178 96 Ave C400
Langley, British Columbia V1M 0B2

Mon to Fri 7:00am–5:00pm

[email protected]

(604) 513-9428

Coleman Technologies Awards & Memberships

Image
Image
Image