Managed web security, filtering what your people reach and run

Managed web security is the outbound half of the filtering story: where mail security screens what arrives, web security screens where your people go and what their browsers pull down, blocking known-malicious destinations, newly registered lookalikes, and the drive-by payloads that turn a misclick into an infection. Delivered managed, it is typically DNS-level or lightweight-agent filtering administered by a provider: they maintain the block categories, tune the exceptions, cover the laptops wherever they work, and report what was blocked and for whom. It is among the cheapest managed protections per user and among the least understood purchases, buyers expect a firewall and receive a policy engine. This guide explains the mechanism in plain terms, the coverage question remote work forces, the category-policy decisions that are yours rather than the provider's, and the honest boundary of what web filtering cannot see, which keeps the purchase in proportion.

The mechanism, in plain terms

When a device looks up where a website lives, the filtered resolver answers normally for clean destinations and refuses for known-bad ones: phishing pages, malware hosts, botnet controllers, the lookalike domain registered yesterday. Agent-based variants extend the same judgement inside the browser's traffic. The mechanism's strengths are breadth and cheapness, every device, every application, one control point, and its judgements ride threat intelligence the provider maintains, which is the managed part: categories updated hourly, exceptions handled by ticket, new-domain caution applied automatically. Its structural weakness is that it judges destinations, not content: a clean site serving a poisoned advert tests other layers.

Coverage, and the remote work question

Filtering applied at the office boundary covers the office, and your laptops live in kitchens. Managed web security earns its keep by travelling: the agent or profile on each device applies the same policy on home wifi, hotel networks and phone hotspots, and the report shows blocks by device wherever they occurred. When evaluating, make roaming coverage the first question, an office-only filter in a hybrid organisation is a partial control sold whole. Second question: unmanaged devices, the personal phone with the work mailbox reaches whatever it likes, and the honest answer combines the device policy, which the free sheet on this site counts into your set, with acceptance that filtering follows management.

Your policy decisions, and the honest boundary

Two decisions are yours, not the provider's. Category policy: beyond the unarguable malicious categories, what else blocks, gambling, adult content, personal storage sites where data walks out? These are conduct and culture decisions belonging in your acceptable use policy, enforced by the filter rather than invented by it. And exception authority: who may approve unblocking a site, in writing, because exception sprawl is how filters quietly die. The boundary to hold in proportion: web filtering reduces the misclick's blast radius; it does not read intent in mail, stop an emailed fraud, or protect credentials typed into a genuinely new phishing page. It is one inexpensive layer of several, and the programme that composes the layers, written, reviewed, owned, is what Hardenvo Pro generates from the set the free sheet counts.

Questions people ask about managed web security

What is managed web security?

Provider-administered DNS or agent-based filtering of where devices go: known-malicious destinations, fresh lookalike domains and drive-by payload hosts blocked, categories maintained hourly, exceptions by ticket, with per-device reporting wherever the device works.

Does web filtering work for remote workers?

Only if it travels: the agent or profile must apply policy on home and public networks, with blocks reported per device. Office-boundary-only filtering in a hybrid organisation is a partial control; make roaming coverage the first evaluation question.

What can't web security filtering do?

It judges destinations, not content or intent: a clean site's poisoned advert, an emailed fraud, or a brand-new phishing page can pass. It is one cheap layer; the acceptable use policy that sets its categories, and the layers around it, complete the control.

Sources

Related answers

Start Hardenvo ProGet Hardenvo Pro, $29 a month