The Situation
Industrial Refrigeration Pros (IR Pros), a fast-growing company with 500 employees and eight business acquisitions since its founding in 2021, understood the importance of scaling its cybersecurity defenses alongside its business.
With multiple IT systems to manage, IR Pros implemented a comprehensive, layered defense strategy. This included a sophisticated email security solution and endpoint protection with Microsoft Defender, working together to safeguard the company from increasingly sophisticated cyber threats.
"It's hard to be perfect when the whole world is trying to attack you. That’s why multiple layers of defense are crucial."
Tom Sweet
CIO, IR Pros
The Problem
Despite these robust defenses, IR Pros encountered a cybersecurity challenge that demonstrated just how cunning today’s threats can be. An employee received an email from a trusted customer—a routine communication they were expecting. Unbeknownst to the employee, the customer had been compromised, and the email contained a malicious link. The email slipped past the company’s defenses and evaded the employee’s instinctual senses, appearing legitimate.
The employee clicked on the link, which is where many organizations might find themselves in serious trouble. However, for IR Pros, this was just the beginning of the story.
Enter DNSFilter
As part of its layered defense strategy, IR Pros had integrated DNSFilter to secure its network at the DNS layer. When the malicious link evaded the initial email defenses, DNSFilter stepped in as the critical safeguard. The query, which used a .gt TLD (used for Guatemala) such as “www[.]example[.]gt,” was instantly blocked.
Additionally, DNSFilter’s Threat Category policy for Malicious Domain Protection, which uses machine learning to analyze query strings and detect threats, would have also blocked the attack, further ensuring the organization’s safety.
The next morning, 18 hours after the incident, Microsoft Defender flagged the issue. By then, DNSFilter had already neutralized the threat. Without DNSFilter, this alert would have triggered an incident response process to deal with a compromised machine.
Tom Sweet, CIO of IR Pros, investigated further and confirmed through the DNS logs that DNSFilter had blocked the query, preventing the malicious site from ever being accessed.
"We deployed DNSFilter on all of our Windows computers, and it has been a key part of our cybersecurity strategy."
Tom Sweet
CIO, IR Pros
Results
DNSFilter’s advanced threat protection not only stopped the attack but also provided additional benefits for IR Pros:
- Advanced Threat Protection: DNSFilter identified and blocked the malicious query in real-time, ensuring that the phishing attempt was thwarted before it could cause harm. As Tom Sweet noted, “DNSFilter blocked the link, so she didn’t actually complete the phish.”
- Minimized Disruption: Had the attack succeeded, the employee’s device would have required a full incident response, including locking the account, removing security tokens, isolating the computer, and performing a complete wipe of the machine. This process would have been highly disruptive to both the employee and the business. Thanks to DNSFilter, this scenario was entirely avoided.
- Flexible and Proactive Security: DNSFilter allows IR Pros to block high-risk TLDs (top-level domains), vanity TLDs, and TLDs from countries where the company doesn’t do business. This capability, combined with the new Malicious Domain Protection policy, played a crucial role in stopping the threat.
Summary
Tom Sweet’s decision to integrate DNSFilter into IR Pros’ multi-layered cybersecurity strategy has been pivotal in enhancing the company’s defenses. As Tom succinctly put it, "It's hard to be perfect when the whole world is trying to attack you. That’s why multiple layers of defense are crucial. We deployed DNSFilter on all of our Windows computers, and it has been a key part of our cybersecurity strategy. Since implementing DNSFilter, our phishing attacks have gone down considerably."
In a world where cyber threats are constantly evolving, DNSFilter stood out as the defense that truly made the difference, blocking the DNS query from ever resolving and ensuring the attack was stopped before it could cause any harm.
dnsUNFILTERED: A CIO's Tale: How They Navigated a Phishing Attack
Hear from Industrial Refrigeration Pros CIO, Tom Sweet, about the phishing attack that almost was.
Fool me once, shame on not using DNS protection
At DNSFilter, we have a global view of what these attackers are doing to fool you into interacting with their malicious website or clicking the link that is part of their multistep process to your compromise.
Migrating from Cisco Umbrella to DNSFilter: A Complete Walkthrough
Ensure that your users and endpoints aren't at risk by seamlessly migrating to a top-tier protective DNS solution.