DNS Security for Canadian SMBs: How CIRA Canadian Shield Blocks Threats Before They Reach Your Devices
Every time an employee opens a browser, clicks a link, or starts an app, their device issues a DNS query — asking the internet's directory service to translate a domain name into an IP address. It happens thousands of times per hour, invisibly, on every device in your organization. And most Canadian SMBs apply no security controls to it whatsoever.
That gap matters because malware exploits DNS aggressively. According to CIRA, 80% of malware uses DNS for command-and-control (C2) communication — meaning that even after ransomware bypasses your email filter and endpoint agent, it still needs to reach its operators via DNS to receive instructions, encrypt your files, and exfiltrate data. A DNS-layer block stops that kill chain at one of its most reliable chokepoints, regardless of how the initial infection occurred.
The good news for Canadian SMBs: there is a free, Canadian-built DNS security tool that the Canadian Centre for Cyber Security explicitly recommends, runs entirely on Canadian servers, and takes under 30 minutes to configure. Most organizations have simply never heard of it.
What Happens at the DNS Layer
Before discussing protection, it helps to understand why DNS is such a productive attack surface.
When your device wants to reach a website, it issues a DNS query: "what IP address corresponds to this domain?" A DNS resolver — typically run by your internet provider — looks up the answer and returns it. The process takes milliseconds and is invisible to end users.
Attackers exploit this in several ways:
Malware command-and-control. Once malware infects a device, it needs to "phone home" to receive instructions and deliver stolen data. To evade IP blocklists, attackers register malicious domains and embed them in malware — the device issues DNS queries to resolve those domains before contacting the attacker's infrastructure. If a DNS resolver refuses to answer those queries, the malware cannot function even after it has been installed.
Phishing via newly registered domains. Phishing infrastructure is almost always newly registered — attackers spin up domains, run a campaign for hours or days, then discard them. DNSFilter's 2025 Annual Security Report found that phishing queries increased 203% in 2025 and that approximately 3.61% of all DNS traffic analyzed was blocked as malicious — the highest quarterly block rate on record. Blocking newly registered or categorized-malicious domains at the DNS layer stops phishing attempts before a browser ever loads the page.
DNS tunneling. Sophisticated attackers exfiltrate data by encoding it inside DNS queries — legitimate-looking requests that carry stolen data out of your network while evading traditional firewall inspection. This technique is used by nation-state threat actors and is increasingly embedded in commercially available malware kits.
The Canadian SMB Exposure
The numbers on DNS-level exposure in Canada are significant.
CIRA's 2025 Cybersecurity Survey — based on 500 Canadian IT professionals surveyed in August 2025 — found that 43% of Canadian organizations experienced a cyber attack in the past 12 months, and 42% reported a breach of customer or employee data — with the steepest year-over-year increase concentrated in the small-business segment.
Statistics Canada's 2023 cybercrime impact survey reported that 1 in 6 Canadian businesses (16%) were impacted by a cybersecurity incident, with Canadian businesses spending $1.2 billion recovering from cyber incidents in 2023 alone — double the $600 million in recovery costs reported in 2021. The pattern is consistent: prevention is significantly cheaper than recovery, and recovery costs are growing faster than prevention investment.
When incidents succeed, the costs compound fast. IBM's 2025 Cost of a Data Breach Report for Canada puts the average Canadian data breach cost at CA$6.98 million — a 10.4% increase from CA$6.32 million the year before.
The forensic link to DNS is consistent across the threat landscape. Research published in CSO Online found that one in 10 organizations has active malware C2 traffic on their networks identifiable through DNS data — meaning active compromises that those organizations are unaware of, communicating through DNS queries that no one is inspecting. DNS-layer monitoring turns an invisible problem into a visible, blockable one.
What the CCCS Recommends
The Canadian Centre for Cyber Security's Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089) includes network and perimeter security as Baseline Control 9 (BC.9). The guidance requires organizations to establish boundary defences that monitor outbound traffic for signs of malicious activity — a requirement that DNS filtering directly addresses.
The CCCS goes further: it explicitly recommends a DNS firewall for small and medium businesses, naming CIRA's Canadian Shield as a tool that satisfies this control. That recommendation is notable — the CCCS does not typically endorse specific commercial products by name. Recommending a Canadian-built, CCCS-threat-intelligence-integrated DNS service in its SMB baseline guidance signals how much weight they place on this control category.
The CCCS National Cyber Threat Assessment 2025–2026 identifies phishing and malware distribution as persistent primary vectors for the cybercrime-as-a-service ecosystem attacking Canadian organizations. Nearly all of those vectors rely on DNS resolution at some point in their attack chain. A resolver that refuses to answer queries for known-malicious domains is one of the most cost-effective interventions against the broadest range of current threats.
For organizations completing a CyberSecure Canada certification or cyber insurance gap assessment, DNS filtering is one of the most underdeployed controls relative to its implementation cost. It takes an afternoon to configure, has no licensing fee at the free tier, and addresses one of the most reliable vectors attackers use to maintain persistence and exfiltrate data.
CIRA Canadian Shield: The Free Option for Canadian Organizations
CIRA Canadian Shield is a free, recursive DNS resolver operated entirely from Canadian servers by the Canadian Internet Registration Authority — the non-profit organization responsible for administering the .ca domain. It is available to any Canadian individual, household, or business at no cost.
Canadian Shield works by acting as your DNS resolver. When a device queries a domain, the resolver checks it against threat intelligence feeds — including real-time input from the Canadian Centre for Cyber Security, which identifies approximately 400 new malicious websites per day and feeds that intelligence directly to CIRA. Combined with Akamai's threat intelligence and additional third-party feeds, CIRA's combined block list covers over 100,000 new malicious domains per day, with new entries added typically within 14 minutes of their first appearance anywhere on the global internet. CIRA data shows 80% of clicks on malware happen in the first eight hours of a campaign going live — meaning speed of detection is as important as breadth of coverage.
If a domain is classified as malicious, the resolver returns nothing: the device cannot connect to it, regardless of what browser or application issued the query.
Privacy by design. Unlike most global DNS resolvers, CIRA Canadian Shield processes all DNS queries on Canadian infrastructure, subject to Canadian privacy law. CIRA does not sell or share DNS query data with third parties. For organizations subject to PIPEDA or sectoral data requirements, this is a meaningful distinction — DNS query logs reveal what domains your employees and customers are attempting to reach, which is sensitive operational data. Keeping that data within a Canadian-governed resolver is the appropriate choice under PIPEDA's accountability framework, and it avoids the vendor-jurisdiction concerns that affect US-headquartered DNS providers.
Three protection tiers:
- Private: Encrypts DNS queries using DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT) to prevent your ISP from logging your DNS lookups — no content filtering
- Protected: Adds malware and phishing domain blocking on top of encryption — the appropriate default for most business deployments
- Family: Adds adult content filtering on top of Protected — relevant for organizations with public-facing devices
For most Canadian SMBs, deploying at the Protected tier at the network router or gateway level is the right default. This extends DNS filtering to every device on the network — including BYOD devices, IoT hardware, shared equipment, and anything else that cannot run an endpoint agent — without requiring per-device configuration.
CIRA DNS Firewall: The Managed Option
For organizations that need policy management, per-user reporting, and cloud-managed controls, CIRA also offers CIRA DNS Firewall — a paid enterprise product that currently protects 3.5 million Canadian users across organizations ranging from SMBs to federal government departments.
The enterprise product adds:
- Granular content category policies (restrict social media, streaming, or non-work categories during business hours)
- Per-device and per-user reporting for incident investigation and compliance evidence
- API integration with SIEM and log management platforms
- Off-network coverage for remote employees through the CIRA DNS Firewall agent
- Dedicated Canadian support and an SLA
The enterprise tier is relevant for organizations that need audit-ready reporting for compliance, managed detection and response integration, or off-network coverage for a distributed remote workforce. For most small businesses without those requirements, the free Canadian Shield Protected tier provides substantive malware and phishing blocking at no cost.
How to Deploy DNS Security This Week
For a small office network, the most impactful deployment takes under 30 minutes:
Step 1 — Router configuration. Log into your network router's admin interface and locate the DNS settings. Replace your current DNS server addresses with CIRA Canadian Shield's Protected tier resolvers:
| Setting | Address |
|---|---|
| Primary DNS | 149.112.121.10 |
| Secondary DNS | 149.112.122.10 |
This applies DNS filtering to every device on the network without touching individual machines.
Step 2 — Verify the configuration. From any device on the network, visit CIRA's Canadian Shield verification page to confirm the resolver is active and which protection tier is in use.
Step 3 — Document the change. Record the router configuration change — the old DNS addresses, the new ones, the date, and the rationale. This documentation supports your CCCS BC.9 compliance and your cyber insurance application if either requires evidence of network perimeter controls.
Step 4 — Cover remote employees. Employees working from home bypass your office router. For remote workers, configure Canadian Shield at their home router level, or deploy the CIRA DNS Firewall agent if you're on the enterprise plan, to extend protection to off-network devices.
For organizations managing devices through Microsoft Intune, DNS policy can be pushed via configuration profiles — applying the CIRA resolver addresses across all managed endpoints without touching individual machines.
The Layer Most Organizations Are Missing
A layered security model for Canadian SMBs typically includes email filtering, endpoint detection and response, multi-factor authentication, and backup. DNS filtering is rarely on that list by default — not because it is ineffective, but because it is invisible. Threats stopped at the DNS layer never reach the endpoint, never trigger the email filter, and never appear in incident reports. They simply do not connect.
CIRA data shows a 90% reduction in desktops impacted by spearphishing attacks when a DNS firewall is deployed alongside email filtering, relative to email filtering alone. The two controls are complementary: email filtering catches the malicious message; DNS filtering catches the connection that the message would have initiated if it got through.
For the cost of 30 minutes of configuration time and zero dollars in licensing fees, CIRA Canadian Shield at the Protected tier delivers network-level malware and phishing blocking, keeps DNS query data within Canadian jurisdiction under Canadian privacy law, and satisfies the CCCS BC.9 network perimeter control — without requiring anything to be installed on individual devices.
Given that CIRA's 2025 survey found 74% of Canadian organizations that experienced ransomware paid the ransom — with average payouts reaching $25,000 — stopping ransomware from phoning home via DNS is one of the cheapest, most reliable interventions available.
Sources
- CIRA. *CIRA Canadian Shield — Free DNS Servers for Canadians.* cira.ca
- CIRA. *CIRA DNS Firewall — Malware Protection Made for Canada.* cira.ca
- CIRA. *How CIRA Canadian Shield Works.* cira.ca
- CIRA. *2025 Cybersecurity Survey.* cira.ca
- CIRA. *The Canadian Centre for Cyber Security Recommends a DNS Firewall for Small and Medium Businesses.* cira.ca
- Canadian Centre for Cyber Security. *Baseline Cyber Security Controls for Small and Medium Organizations (ITSM.10.089).* cyber.gc.ca
- Canadian Centre for Cyber Security. *National Cyber Threat Assessment 2025–2026.* cyber.gc.ca
- Statistics Canada. *The Daily — Impact of Cybercrime on Canadian Businesses, 2023.* October 21, 2024. statcan.gc.ca
- IBM. *Cost of a Data Breach Report 2025 — Canada.* canada.newsroom.ibm.com
- DNSFilter. *2025 Annual Security Report: Worrisome Spike in Malicious DNS Requests.* dnsfilter.com
- CSO Online. *DNS Data Shows One in 10 Organizations Have Malware Traffic on Their Networks.* csoonline.com
Cloud Forces helps Canadian SMBs configure DNS security controls, deploy CIRA Canadian Shield and DNS Firewall across managed endpoints and remote workforces, and build the documented network perimeter evidence that CCCS compliance and cyber insurance renewals increasingly require. Explore our Cybersecurity services or contact us to book a complimentary network security review.
Anton Kuznetsov is the founder and principal engineer of Cloud Forces, the Toronto firm he started in 2018 to make custom software and AI practical and affordable for Canadian SMEs. He works hands-on across application development, cloud architecture, and the production systems Cloud Forces runs for its clients.
Ready to bring AI to your business?
Book a free AI Readiness Consultation — no commitment required.
Book Free Consultation