New — Guardian: one-tap online safety for every device. Free on every plan.
Business · Included free on every plan

Guardian.Threat filtering across every device on the office Wi-Fi.

One control. Every laptop, POS, printer, IoT sensor, guest phone. Zero agents.

Guardian is Giant’s built-in DNS-layer threat filter — it blocks malware, phishing, credential theft and (optionally) adult content across every device on your business Wi-Fi. Sits above the router so it covers what you can’t put an agent on: POS terminals, printers, badge readers, IoT sensors, guest devices, contractor laptops. Included free on every Giant business broadband + leased-line service.

No agents · No per-seat licence · Zero speed impact

01Why business Guardian

Six reasons this matters more at a business.

Guardian's mechanics are the same as our residential product — same DNS-layer control, same feeds, same free-on-every-plan pricing. The pay-off is bigger for a business because the attack surface, blast radius and compliance friction all are.

01

Every device — including the ones you can't put agents on

Endpoint antivirus needs an agent per device. Guardian sits upstream, so it also covers the POS terminal, the wireless printer, the smart display, the badge reader, the guest laptop, the contractor's tablet. If it uses your Wi-Fi, it's covered.

02

No per-seat licence to manage

Add a headcount → covered. Bring on a contractor → covered. Guest device → covered. The whole line is covered for a flat price (which is £0, because Guardian's included). Contrast with per-seat endpoint fleets that scale linearly with your business.

03

UK-current threat intelligence

Giant is a UK ISP. Fake HMRC 'tax rebate' pages, spoof Royal Mail portals, DVLA impersonators — that traffic hits our own network as it launches, so our threat feeds catch UK-specific scams hours before global blocklists update.

04

Consistent across every site

Chains, franchises, multi-office businesses: Guardian gives you the same baseline threat coverage at every Giant line, without a per-site rollout or engineer visit. Add a new office, add a Giant line, Guardian is on.

05

Zero latency added, zero bandwidth cost

Guardian is a DNS-layer check on lookups that happen anyway. It doesn't proxy traffic, doesn't inspect payloads, doesn't sit in the packet path. Multi-gig lines still hit line rate.

06

One line on your Cyber Essentials / IASME report

Network-level threat filtering is a documented control in Cyber Essentials, IASME and most cyber-insurance renewal questionnaires. Guardian is a checkbox tick backed by a working control — not a policy without a mechanism.

Every device on the line — no exceptions, no agents, no seat count.

Because Guardian sits at the network layer, the things you can't install an endpoint on (POS, printers, IoT, guest devices) are exactly what it protects best.

See the coverage
02Coverage

The device zoo. All of it, covered.

Modern offices have 3-5× more networked devices than staff — POS, printers, badge readers, smart displays, IoT sensors, coffee machines with default credentials. Endpoint agents can't reach any of them. Guardian's above the router, so they're all in scope.

Staff laptops + desktops
Contractor + consultant devices on your Wi-Fi
Guest devices on the guest SSID
Point-of-sale terminals
Network printers + copiers
IoT — thermostats, cameras, badge readers, digital signage
Meeting-room kit (Teams Rooms, Zoom Rooms, TVs)
Smart-building sensors, HVAC controllers, coffee machines
03Three levels

Pick your level.

Off if you already run equivalent DNS filtering upstream. Standard for the default business case. Content for schools, nurseries, community spaces + hospitality operators serving guest Wi-Fi.

Guardian Off

Standard business internet — nothing filtered by Giant. For teams running their own DNS filtering, a next-gen firewall, or SASE stack that duplicates the coverage.

What it blocks
  • Nothing — traffic passes through unmodified.
Who it's for

You already run a firewall / SD-WAN / SASE with equivalent DNS filtering (Cisco Umbrella, DNSFilter, Cloudflare Gateway, NextDNS Business, PiHole at scale).

Recommended

Guardian Standard

Automatic blocking of the categories that hit UK businesses every day — phishing, malware distribution, credential theft, ransomware C2, freshly-registered scam domains. On by default across every device on your line.

What it blocks
  • Known malware distribution + drive-by download hosts
  • Phishing pages (fake HMRC, fake banks, fake M365 logins)
  • Credential-harvesting sites + look-alike domains
  • Newly-registered domains commonly used in short-lived scam campaigns
  • Ransomware command-and-control servers we've seen active
Who it's for

Every business with a Wi-Fi network. Default choice — no false positives on legitimate sites, no productivity hit, no per-seat licence to track.

Schools / hospitality

Guardian Content

Everything Standard blocks, PLUS a broad content layer. On business Wi-Fi this is normally used by schools, nurseries, community centres, hotels + hospitality venues to reduce accidental exposure on guest / staff / student devices.

What it blocks
  • Everything in Standard (malware, phishing, credential theft)
  • Adult content across the major categories
  • Common bypass services (VPN portals, proxy sites) that would route around the filter
Who it's for

Schools, nurseries, childcare, community spaces, hospitality, guest-Wi-Fi providers. NOT a substitute for a formal safeguarding policy or DPIA — a network-level baseline that complements them.

What Guardian isn’t

Guardian is DNS-layer filtering, not endpoint protection. Anything that reaches the device (a USB stick, an email attachment) is out of scope — that’s what your endpoint AV / EDR is for. Determined bypass attempts (VPNs, DNS-over-HTTPS on a device, staff hotspotting off mobile) can route around Guardian; it’s a strong network baseline, not a total endpoint control.

04Where the case is sharpest

Business Guardian by sector.

The mechanism's the same everywhere; what varies is what a breach costs. Six sectors where the ratio of Guardian's zero cost to blocked-breach value is starkest.

Retail + hospitality

POS terminals + payment devices + staff tablets + a guest SSID for customers. Guardian blocks the malware families that target retail (Magecart, POS skimmers, credential stealers on the till PC) and stops guest devices dragging phishing links into the network.

Legal + accountancy

Client-money is a top target for CEO-fraud and payment-diversion phishing. Guardian's UK-specific feed catches fake HMRC / Companies House / bank pages fast, and the newly-registered-domain block traps the short-life spoofs Google Safe Browsing hasn't classified yet.

Healthcare + professional services

Ransomware runs on domain lookups it can't finish. Guardian blocks the C2 domains commonly used by active ransomware families, cutting the kill-chain before file-encryption starts. One control, applied network-wide.

Schools + childcare

Guardian Content adds an adult-content block across every device on the school Wi-Fi — including tablets brought in for lessons, staff phones and contractor kit. NOT a replacement for your safeguarding policy; a network-level layer beneath it.

Multi-site + guest Wi-Fi providers

Landlords, coworking, hotels, cafés, and other operators serving guest Wi-Fi carry duty-of-care exposure for what's accessed on the SSID. Guardian is a baseline that shows demonstrable steps to filter harmful / illegal content without deploying a dedicated captive portal fleet.

Charities + community spaces

Small IT team, mixed device estate, volunteers on borrowed kit, a public Wi-Fi for service users. Guardian is threat filtering that doesn't need a security specialist to run — it's on the moment your Giant line goes live and there's nothing to configure.

05How Guardian works

Runs on our network. Not your kit.

No appliance to buy, no agent to deploy, no captive portal to run. Because Guardian filters at the DNS layer on Giant's network, it starts working the moment your business line goes live and stays running for the life of the service.

Step 01

Runs on our network, not your kit

Guardian filters at Giant's network level — no on-prem appliance, no agent to deploy on 50 laptops, no captive portal to maintain. Traffic bound for a blocked domain never leaves your line.

Step 02

Every device, no discrimination

Staff laptop, guest phone, printer, POS, IoT sensor. Guardian covers them all because it sits above the router. The devices you can't put endpoint agents on are exactly the ones Guardian was designed for.

Step 03

Zero business impact

DNS filtering, not deep-packet inspection. Multi-gig line still hits multi-gig. Video calls still work. Cloud backups still stream. Guardian is invisible until it blocks something bad.

Step 04

Change it in seconds, in the portal

Level change is a single click in portal.giant.net.uk. No support ticket, no change-request window, no engineer visit. Off / Standard / Content — pick one, apply, done.

06Compliance framing

One line in your compliance report.

Guardian is a documented technical control that maps to boxes in every UK business-security framework we've been asked about. Not the whole answer to any of them — a real, working control that helps you tick them faster and cheaper.

Cyber Essentials
Control · Boundary firewalls / secure configuration
Guardian · Guardian sits at the network boundary as a DNS-layer control. Complements (does not replace) a hardware firewall — most Cyber Essentials assessors accept both together as a stronger perimeter posture than firewall alone.
IASME Cyber Baseline
Control · Protective monitoring, secure configuration
Guardian · Documented DNS filtering + threat-feed subscription counts toward the monitoring control. Free at every site simplifies multi-site rollout evidence.
PCI-DSS (small-merchant)
Control · Requirement 1 (network segmentation), Requirement 5 (malware)
Guardian · Guardian blocks the domains used by common POS-skimmer + card-scraper malware. Doesn't remove PCI scope on its own, but it's one demonstrable control for merchants renewing self-assessment.
GDPR / DPIA
Control · Article 32 (appropriate technical measures)
Guardian · Blocking known phishing + credential-theft sites is an appropriate technical measure to reduce accidental data-subject exposure. Feature-in-baseline, not an add-on, so easier to describe in a DPIA.
Cyber-insurance renewal
Control · Threat filtering questionnaire
Guardian · Most cyber-insurance questionnaires now ask 'do you deploy DNS-layer threat filtering across all sites?' — Guardian is a yes on every Giant line, with the same underlying feed at every site.

Guardian is a control, not an accreditation. It doesn’t on its own certify you against any of these frameworks — but it’s a documented, demonstrable technical measure that ticks a real control-box in each of them, at zero incremental cost.

07Turn it on

15 seconds from portal to live.

Guardian's already active on Standard for every business line. If you want to change level (or run without it), the whole flow is three clicks in portal.giant.net.uk — no ticket, no engineer visit, no change-window.

    01

    Log in to portal.giant.net.uk

    Your account admin has access on day one — no separate Guardian login.

    02

    Services → your line → Guardian

    Pick Off / Standard / Content. Change is live at the next DNS lookup.

    03

    Applies to every device on the line

    No rollout, no re-image, no user comms. The new level is in effect across every device the moment you click Save.

08FAQ

Guardian for business, answered honestly.

No. Endpoint AV / EDR runs on the device — it can see local file activity, quarantine executables, roll back ransomware changes. Guardian runs on the network — it blocks connections to known-bad domains before they happen. The two are complementary. Guardian catches the delivery attempt (the phishing link, the C2 domain lookup); endpoint tools handle anything that lands on the device. Most defensive stacks want both.

On the moment your business line goes live.

Guardian is a feature of being a Giant business customer — check whether we can deliver a fast line at your office and Guardian’s on with the service from day one.

No coverage yet? Mid-contract elsewhere? Join the waitlist or set a contract-end reminder — we'll ping you when it's the right moment to switch.

Real customers

What people actually say.

5.0/5 from 72 customer reviews — same Giant team every one of them dealt with.

See all 72 reviews on Trustpilot

Or leave one of your own — opens Trustpilot in a new tab