Guardian.Threat filtering across every device on the office Wi-Fi.
One control. Every laptop, POS, printer, IoT sensor, guest phone. Zero agents.
Guardian is Giant’s built-in DNS-layer threat filter — it blocks malware, phishing, credential theft and (optionally) adult content across every device on your business Wi-Fi. Sits above the router so it covers what you can’t put an agent on: POS terminals, printers, badge readers, IoT sensors, guest devices, contractor laptops. Included free on every Giant business broadband + leased-line service.
No agents · No per-seat licence · Zero speed impact
Six reasons this matters more at a business.
Guardian's mechanics are the same as our residential product — same DNS-layer control, same feeds, same free-on-every-plan pricing. The pay-off is bigger for a business because the attack surface, blast radius and compliance friction all are.
Every device — including the ones you can't put agents on
Endpoint antivirus needs an agent per device. Guardian sits upstream, so it also covers the POS terminal, the wireless printer, the smart display, the badge reader, the guest laptop, the contractor's tablet. If it uses your Wi-Fi, it's covered.
No per-seat licence to manage
Add a headcount → covered. Bring on a contractor → covered. Guest device → covered. The whole line is covered for a flat price (which is £0, because Guardian's included). Contrast with per-seat endpoint fleets that scale linearly with your business.
UK-current threat intelligence
Giant is a UK ISP. Fake HMRC 'tax rebate' pages, spoof Royal Mail portals, DVLA impersonators — that traffic hits our own network as it launches, so our threat feeds catch UK-specific scams hours before global blocklists update.
Consistent across every site
Chains, franchises, multi-office businesses: Guardian gives you the same baseline threat coverage at every Giant line, without a per-site rollout or engineer visit. Add a new office, add a Giant line, Guardian is on.
Zero latency added, zero bandwidth cost
Guardian is a DNS-layer check on lookups that happen anyway. It doesn't proxy traffic, doesn't inspect payloads, doesn't sit in the packet path. Multi-gig lines still hit line rate.
One line on your Cyber Essentials / IASME report
Network-level threat filtering is a documented control in Cyber Essentials, IASME and most cyber-insurance renewal questionnaires. Guardian is a checkbox tick backed by a working control — not a policy without a mechanism.
Every device on the line — no exceptions, no agents, no seat count.
Because Guardian sits at the network layer, the things you can't install an endpoint on (POS, printers, IoT, guest devices) are exactly what it protects best.
The device zoo. All of it, covered.
Modern offices have 3-5× more networked devices than staff — POS, printers, badge readers, smart displays, IoT sensors, coffee machines with default credentials. Endpoint agents can't reach any of them. Guardian's above the router, so they're all in scope.
Pick your level.
Off if you already run equivalent DNS filtering upstream. Standard for the default business case. Content for schools, nurseries, community spaces + hospitality operators serving guest Wi-Fi.
Guardian Off
Standard business internet — nothing filtered by Giant. For teams running their own DNS filtering, a next-gen firewall, or SASE stack that duplicates the coverage.
- Nothing — traffic passes through unmodified.
You already run a firewall / SD-WAN / SASE with equivalent DNS filtering (Cisco Umbrella, DNSFilter, Cloudflare Gateway, NextDNS Business, PiHole at scale).
Guardian Standard
Automatic blocking of the categories that hit UK businesses every day — phishing, malware distribution, credential theft, ransomware C2, freshly-registered scam domains. On by default across every device on your line.
- Known malware distribution + drive-by download hosts
- Phishing pages (fake HMRC, fake banks, fake M365 logins)
- Credential-harvesting sites + look-alike domains
- Newly-registered domains commonly used in short-lived scam campaigns
- Ransomware command-and-control servers we've seen active
Every business with a Wi-Fi network. Default choice — no false positives on legitimate sites, no productivity hit, no per-seat licence to track.
Guardian Content
Everything Standard blocks, PLUS a broad content layer. On business Wi-Fi this is normally used by schools, nurseries, community centres, hotels + hospitality venues to reduce accidental exposure on guest / staff / student devices.
- Everything in Standard (malware, phishing, credential theft)
- Adult content across the major categories
- Common bypass services (VPN portals, proxy sites) that would route around the filter
Schools, nurseries, childcare, community spaces, hospitality, guest-Wi-Fi providers. NOT a substitute for a formal safeguarding policy or DPIA — a network-level baseline that complements them.
Guardian is DNS-layer filtering, not endpoint protection. Anything that reaches the device (a USB stick, an email attachment) is out of scope — that’s what your endpoint AV / EDR is for. Determined bypass attempts (VPNs, DNS-over-HTTPS on a device, staff hotspotting off mobile) can route around Guardian; it’s a strong network baseline, not a total endpoint control.
Business Guardian by sector.
The mechanism's the same everywhere; what varies is what a breach costs. Six sectors where the ratio of Guardian's zero cost to blocked-breach value is starkest.
Retail + hospitality
POS terminals + payment devices + staff tablets + a guest SSID for customers. Guardian blocks the malware families that target retail (Magecart, POS skimmers, credential stealers on the till PC) and stops guest devices dragging phishing links into the network.
Legal + accountancy
Client-money is a top target for CEO-fraud and payment-diversion phishing. Guardian's UK-specific feed catches fake HMRC / Companies House / bank pages fast, and the newly-registered-domain block traps the short-life spoofs Google Safe Browsing hasn't classified yet.
Healthcare + professional services
Ransomware runs on domain lookups it can't finish. Guardian blocks the C2 domains commonly used by active ransomware families, cutting the kill-chain before file-encryption starts. One control, applied network-wide.
Schools + childcare
Guardian Content adds an adult-content block across every device on the school Wi-Fi — including tablets brought in for lessons, staff phones and contractor kit. NOT a replacement for your safeguarding policy; a network-level layer beneath it.
Multi-site + guest Wi-Fi providers
Landlords, coworking, hotels, cafés, and other operators serving guest Wi-Fi carry duty-of-care exposure for what's accessed on the SSID. Guardian is a baseline that shows demonstrable steps to filter harmful / illegal content without deploying a dedicated captive portal fleet.
Charities + community spaces
Small IT team, mixed device estate, volunteers on borrowed kit, a public Wi-Fi for service users. Guardian is threat filtering that doesn't need a security specialist to run — it's on the moment your Giant line goes live and there's nothing to configure.
Runs on our network. Not your kit.
No appliance to buy, no agent to deploy, no captive portal to run. Because Guardian filters at the DNS layer on Giant's network, it starts working the moment your business line goes live and stays running for the life of the service.
Runs on our network, not your kit
Guardian filters at Giant's network level — no on-prem appliance, no agent to deploy on 50 laptops, no captive portal to maintain. Traffic bound for a blocked domain never leaves your line.
Every device, no discrimination
Staff laptop, guest phone, printer, POS, IoT sensor. Guardian covers them all because it sits above the router. The devices you can't put endpoint agents on are exactly the ones Guardian was designed for.
Zero business impact
DNS filtering, not deep-packet inspection. Multi-gig line still hits multi-gig. Video calls still work. Cloud backups still stream. Guardian is invisible until it blocks something bad.
Change it in seconds, in the portal
Level change is a single click in portal.giant.net.uk. No support ticket, no change-request window, no engineer visit. Off / Standard / Content — pick one, apply, done.
One line in your compliance report.
Guardian is a documented technical control that maps to boxes in every UK business-security framework we've been asked about. Not the whole answer to any of them — a real, working control that helps you tick them faster and cheaper.
Guardian is a control, not an accreditation. It doesn’t on its own certify you against any of these frameworks — but it’s a documented, demonstrable technical measure that ticks a real control-box in each of them, at zero incremental cost.
15 seconds from portal to live.
Guardian's already active on Standard for every business line. If you want to change level (or run without it), the whole flow is three clicks in portal.giant.net.uk — no ticket, no engineer visit, no change-window.
Log in to portal.giant.net.uk
Your account admin has access on day one — no separate Guardian login.
Services → your line → Guardian
Pick Off / Standard / Content. Change is live at the next DNS lookup.
Applies to every device on the line
No rollout, no re-image, no user comms. The new level is in effect across every device the moment you click Save.
Guardian for business, answered honestly.
On the moment your business line goes live.
Guardian is a feature of being a Giant business customer — check whether we can deliver a fast line at your office and Guardian’s on with the service from day one.
No coverage yet? Mid-contract elsewhere? Join the waitlist or set a contract-end reminder — we'll ping you when it's the right moment to switch.
