Web filtering for business:

how it protects your staff, data, and AI tools

If you run a business in Bristol, Bath, Cheltenham, Swindon, Gloucester, or anywhere across the South West, your staff are accessing the internet every day – and not all of it is safe. At We Do Your IT Support, we use web filtering to stop staff from reaching malicious websites, phishing attacks, and risky AI tools before the page even loads.

 

Web filtering is about controlling internet access in a smart, automated way. It is not about spying on your team’s activity. It is one layer in a wider security stack alongside endpoint protection, email security, and data governance, and it can be delivered as a cloud based service with no hardware to buy. This article covers what web filtering is, why a firewall alone is not enough, the difference between dns filtering and endpoint web filtering, what gets blocked (including AI tools), how ThreatLocker Web Control fits in, Cyber Essentials, and practical steps for getting it in place.

What is web filtering in plain English?

Web filtering is a security layer that checks every website request against a blocklist and a set of company rules before the page loads. If the destination is known to be malicious, used in phishing attempts, or violates your company’s security policies, the connection is blocked before any web content reaches the device.

Here is how it works in practice:

To give some scale to the problem: over 17 million websites are currently infected with malware. In 2025, researchers identified over 100 million newly observed domains in a single year, with roughly a quarter classified as malicious or suspicious. Fake Microsoft 365 login pages designed to steal login credentials remain one of the most common phishing attacks, while ransomware download sites and command-and-control domains continue to target SMBs.

Web filtering also covers productivity and content policy. Employers use web filtering to increase employee productivity by restricting non-work-related sites – for example, limiting access to gambling, adult content, or high-risk streaming during working hours. Web filtering improves employee productivity by minimising distractions, and it optimises network performance by managing bandwidth usage. It does not need to be heavy-handed; policies can be tuned to your business.

Url filtering allows or blocks access based on website URLs, so you can target specific web pages rather than blocking an entire website. For SMBs, modern web filtering is usually delivered as a lightweight agent or cloud based service – there is no need for a large on-site appliance.

Why a firewall alone is not enough

A traditional firewall protects the network perimeter. It sits at the boundary of your office network and controls what comes in and goes out based on rules – ports, IP addresses, and basic traffic types. When everyone worked in the office, plugged into the same network, that was often enough for basic network security.

 

That is no longer how most businesses operate. Staff now work from home on domestic routers, connect laptops via public Wi-Fi in cafés, and use mobile devices from client sites. Once a device leaves the office, it is outside the protection of your corporate network firewall. Clicking a malicious link at home or on hotel Wi-Fi can still compromise business data, email, and cloud services.

 

Web filtering at the DNS or endpoint level travels with the device, so web protection applies wherever staff connect to the internet. Cloud-based web filtering provides flexible protection for remote workers – whether they are at home in Bath or visiting a client in London. Web filtering enhances network security by blocking access to malware sites regardless of the network the device sits on.

 

Consider a bring your own device scenario: a salesperson uses their personal laptop to check work email from a customer meeting. Without endpoint web filtering, that device has no protection against harmful sites. With an agent installed, the device still blocks malicious web pages, phishing sites, and unwanted content – without needing to control the home router or public dns resolver.

 

Even inside the office, a firewall relying on static rules cannot keep pace with the thousands of new malicious sites created every day. Modern filtering pulls in live threat intelligence feeds, so your protection updates automatically. Unrestricted internet access, whether in the office or out of it, is a security risk no business should accept.

Adobestock 578088279 scaled 1.jpeg - We Do Your IT Support Bristol

DNS filtering vs endpoint web filtering

Both dns filtering and endpoint web filtering are forms of web filtering, but they work at different points in the connection and suit different situations.

DNS filtering

DNS filtering intercepts requests when a device tries to look up a domain name. When someone tries to visit a website, the device sends dns queries to a resolver. DNS filtering uses blocklists to restrict harmful domains – if the domain is flagged, the connection is refused before any data is transferred. DNS filtering blocks websites at the domain level and blocks access to malicious websites. A specially configured dns resolver or dns filtering services can be set up by changing the DNS settings on your office router or firewall, making it straightforward to deploy across a single site. Dns layer security is effective for on-premises offices and simple networks.

DNS filtering helps block phishing websites before they load and can prevent some types of malware attacks. It is worth noting that 90% of businesses experience DNS attacks each year, so dns filtering helps reduce that exposure. However, dns filtering is network-centric: if a device connects to a different network (home broadband, public Wi-Fi), the filtering may no longer apply unless the device is configured to use the same public dns resolver.

Endpoint web filtering

Endpoint web filtering is software installed on each laptop, desktop, or server. It monitors and controls web access from that device, regardless of which network it is connected to. It can inspect full URLs, subdomains, browser behaviour, and even application-level web traffic. This is what makes it ideal for remote and hybrid workers, as the filtering solution travels with the device.

DNS filteringEndpoint web filtering
Where it worksOn the network (router/DNS settings)On each device (agent installed)
Travels with the device?Only if device DNS is lockedYes – works on any network
GranularityDomain-level blockingFull URL, subdomain, category, app-level
Best forFixed office, single-site, shared Wi-FiRemote workers, hybrid teams, BYOD, multi-site
SetupChange DNS settings on routerInstall agent on each endpoint

For most SME clients across the South West, We Do Your IT Support favours endpoint-level web filtering. It delivers consistent protection whether people are in Bristol, at home in Bath, or meeting a client in London. It covers internal users and anyone on a bring your own device arrangement, without depending on the office router.

What web filtering blocks – and why it matters for AI tools

Modern web filtering does more than block a few dodgy websites. It enforces web security, compliance, and acceptable use, including how staff interact with AI tools.

Threat categories blocked:

Content and keyword controls:

Content filtering and category filtering block websites based on content type categories – for example, adult content, gambling, illegal streaming, and extremist material. Restricting access to inappropriate content reduces legal liability for organisations and supports a secure and productive environment. Keyword filtering restricts access based on specific keywords, adding another layer where needed. Secure web gateways conduct deep content inspection for regulatory compliance, though most SMBs will find category and domain-based controls more than sufficient for day-to-day web content filtering.

AI tools and shadow AI:

This is where things get increasingly relevant. Staff can paste confidential data – client details, HR records, financial spreadsheets – into unapproved AI tools without realising the risk. Web filtering allows you to block users from accessing websites based on domain, so you can restrict access to consumer AI chatbots while allowing approved tools like Microsoft Copilot. Web filtering prevents unauthorised data transfers and reduces the risk of data breaches.

Reporting from a good filtering solution shows which sites and tools are being accessed or blocked, helping business owners understand real usage patterns without reading individual web activity line by line. This visibility is essential for managing shadow AI and supporting data protection.

How ThreatLocker Web Control works (our preferred filtering solution)

We Do Your IT Support deploys ThreatLocker Web Control as part of our AI Security Pack for South West SMBs. It is our preferred web filtering solution because it is endpoint-based, requires no on-site hardware, and delivers advanced web filtering without complexity.

How it works in practice

ThreatLocker Web Control sits on each Windows endpoint and server. Because the agent is on the device, controls and protections follow the user wherever they work – in the office, at home, or on public Wi-Fi. This is what makes it a comprehensive solution for businesses with hybrid or remote staff.

Category and domain controls

The tool uses category-based blocking to filter content. Categories include malicious websites, phishing, adult content, gambling, and unapproved AI tools. Alongside categories, you can set up allow-lists and deny-lists for specific websites or specific sites, giving precise control over which websites users can reach. It acts as an advanced features layer on top of basic threat protection, covering web access across all major web browsers.

Policies can be tailored by role. Marketing might need access to social media platforms, while finance does not. We Do Your IT Support helps design these rules in plain English with sensible defaults and a user friendly interface for requesting access to blocked sites when justified.

Continuous updates and no hardware

ThreatLocker’s blocklist and threat intelligence are continuously updated. Cloud web filtering uses machine learning to detect emerging threats, and real-time threat detection is essential for modern web filters – new phishing domains, C2 domains, and malicious adtech are caught without constant manual tweaking.

There is no need to buy or manage a web filtering appliance. Cloud-based web filters can reduce costs by 60% compared to traditional on-premise hardware, and cloud-based filters offer high scalability for growing businesses. Deployment is done remotely by We Do Your IT Support, usually in a matter of hours, with minimal disruption.

ThreatLocker Web Control integrates into a layered security approach alongside endpoint protection, email filtering, backup, and data governance tools we already manage for clients. It is not a standalone silver bullet – it is one part of a practical, proven stack.

Web filtering and Cyber Essentials

Cyber Essentials is the UK government-backed scheme that sets a baseline for cyber security for businesses of all sizes. Many SMBs across the South West pursue certification to win contracts, satisfy procurement requirements, or meet insurer expectations.

 

The relevant requirement, in plain English: Cyber Essentials expects organisations to have boundary firewalls and internet gateways that restrict access to only the services and websites needed for business purposes. Implementing web filtering is a practical way to demonstrate this control – showing that the business blocks access to malicious and unnecessary sites and has a clear acceptable use policy for internet usage. Web filtering helps organisations comply with legal and regulatory standards, including Cyber Essentials.

 

The current version of the scheme (v3.3, Montpellier) clarifies that personal devices used for business and cloud services cannot be excluded from scope. This means that traditional network-only controls can leave a gap for remote staff and home workers. Endpoint-based web filtering such as ThreatLocker Web Control helps meet the requirement wherever devices are used – protecting users whether they are in the office or working from a home network with unknown internet security settings.

 

Logs and reports from the filtering solution can be used as evidence during a Cyber Essentials or Cyber Essentials Plus assessment. They show how network access and internet access are controlled, which categories are blocked, and how threat protection is maintained. We Do Your IT Support can align web filtering policies with Cyber Essentials controls, so your business is not just technically compliant but practically safer day-to-day.

Cyber Essentials: what web filtering addresses

Controlling AI tool usage with web filtering

Since 2023, tools like ChatGPT, Google Gemini, and dozens of niche AI services have made it easy for staff to paste sensitive data into third-party systems without thinking twice. Gartner predicts 17% of cyberattacks will use generative AI by 2027, and the risk from unapproved AI tool usage is growing just as fast.

Web filtering allows businesses to define which AI tools are allowed – for example, Microsoft Copilot within Microsoft 365 – and which are blocked by default, such as personal ChatGPT accounts and consumer AI chatbots. This is done through allow-list and deny-list rules at the domain and subdomain level.

We typically configure ThreatLocker Web Control so that all external AI chatbot domains are blocked for general staff. If someone tries to visit an unapproved AI site, a block page appears. They can request access if justified, subject to IT review. Meanwhile, approved tools like Copilot remain available through the correct, business-controlled channel.

This reduces the risk of staff accidentally leaking client data, HR information, sensitive data, or financial records into AI tools whose terms, storage locations, and data protection standards the business does not control.

Blocking can be tailored: a policy might allow the IT or R&D team wider access to AI tools for testing, while restricting general users to a small, approved list. Web filtering reports show how often blocked AI tools are being attempted, giving business owners insight into shadow AI usage and helping guide training and policy updates. This supports wider AI governance without blocking access to innovation entirely.

What we configure in ThreatLocker

FAQs

What is web filtering for business?

Web filtering for business is a control that decides which websites and online services staff can reach, based on safety and company policy, before any web pages load. It blocks malicious websites, phishing pages, malicious content, and inappropriate websites – and We Do Your IT Support manages it so business owners do not need technical skills. If a member of staff clicks a phishing link, they see a warning block page instead of the fake login screen. It protects users from accessing websites that could compromise the business, and lets you filter content based on your own acceptable use rules.

DNS filtering works at the dns level by controlling which domains can be looked up via dns queries. It uses a specially configured dns resolver or public dns resolver to intercept requests across a network, making it effective for fixed offices and simple networks. It operates within an anycast network infrastructure for speed and reliability. Endpoint web filtering runs on each device and makes decisions locally, regardless of the network. It covers laptops, remote workers, and bring your own device arrangements. We Do Your IT Support mainly deploys endpoint filtering via ThreatLocker Web Control so web protection follows the device wherever it goes – no matter the network.

Yes. Endpoint-based web filtering works wherever the device has internet access – home broadband, hotel Wi-Fi, 4G hotspot – because the control is on the laptop, not the office router. If a staff member working from home clicks a malicious link in a phishing email, the site is blocked even though they are off the corporate network. This is particularly important for businesses with hybrid working across Bristol, Bath, and remote locations. Cloud-based web filtering provides flexible protection for remote workers and ensures consistent internet security across the business.

Cyber Essentials does not always use the words “web filtering”, but it does require boundary firewalls and internet gateways that restrict access to what is necessary for business. Using web filtering is one of the simplest ways to meet and evidence this requirement, especially for remote staff. ThreatLocker Web Control and supporting security policies can be configured to align with Cyber Essentials expectations. We Do Your IT Support helps with both configuration and the assessment questionnaire.

Yes. Web filtering can block or allow specific AI tools by domain, so businesses can choose to block users from accessing personal ChatGPT accounts or other AI chatbots while allowing Microsoft Copilot or other approved services. This reduces the chance of staff pasting sensitive data into uncontrolled AI platforms, helping protect users and supporting wider AI governance. We Do Your IT Support includes these AI controls in our AI Security Pack, with ThreatLocker Web Control at the endpoint. It also helps you manage which specific websites are accessible, and block malicious content from AI-adjacent services.

Next steps: getting web filtering in place without new hardware

You do not need to buy a new firewall appliance or replace your internet connection to get effective web filtering in place. Cloud web filtering can reduce overall costs by 60% for businesses compared to traditional hardware, and modern solutions are designed for SMBs – not just large enterprises.

Here is how onboarding typically works with We Do Your IT Support:

How onboarding works:

This is part of a layered security approach including endpoint protection, email security, and data governance. It supports a secure and productive environment without creating friction for your team. Web filtering is not a standalone silver bullet – it is one essential layer.

Ready to take the next step? Contact We Do Your IT Support today to book a Copilot security review or enquire about our AI Security Pack. Whether you are in Bristol, Bath, Cheltenham, Swindon, Gloucester, or anywhere across the South West, we offer both remote and on-site support to get web filtering and AI controls working for your business – with no pressure, no jargon, and no hardware to buy.

Senior, happy man and call center with headphones in customer service, support or telemarketing at office. Mature businessman