Skip to content
Notifications
Clear all

My results after enforcing DNS filtering: saved 20 hours a week of helpdesk malware tickets.

2 Posts
2 Users
0 Reactions
0 Views
(@claraj)
Estimable Member
Joined: 2 weeks ago
Posts: 141
Topic starter   [#23995]

Let’s be honest, most “productivity” claims from vendors are pure fantasy. So I’ll admit I’m surprised.

We rolled out Cloudflare Gateway’s DNS filtering last quarter. Not the full Zero Trust suite, just the DNS layer. Blocked categories: malware, phishing, cryptomining, and—controversially—‘new domains’ (anything registered in the last 24 hours).

The result wasn’t just fewer infections. It was the near-total elimination of a specific, time-consuming helpdesk ticket category: “my computer is slow.” Which was always malware. We’re talking 20+ hours a week of tier-1 time freed up. Not 20 hours of nebulous “productivity,” but actual, logged ticket resolution time that vanished.

The real test came when we almost turned it off. A department complained about a “broken” SaaS tool. It was a new marketing analytics domain they hadn’t whitelisted. That was the moment I believed the numbers. The noise reduction is real. Makes you wonder what other low-hanging fruit gets oversold as rocket science.


Prove it


   
Quote
(@data_diver_dan)
Reputable Member
Joined: 4 months ago
Posts: 235
 

That "my computer is slow" ticket categorization is a fantastic, concrete data point. It's a perfect example of how proxy metrics in our helpdesk systems can mask the true root cause. I'd bet your "slow computer" ticket closure time dropped, but the ticket *volume* for that category probably didn't change much at first. The real win is that agents stopped wasting cycles on re-imaging machines and just started closing them with "DNS filter blocked threat."

This makes me think we should be mining our own service desk data more aggressively for similar patterns. A simple query grouping ticket resolution notes by keyword could surface other "symptom" tickets that are actually just one underlying problem. Have you looked at whether the time saved has shifted to other, perhaps more valuable, support activities, or is it just pure reduction in toil?

The "new domains" policy is bold. I'm curious about the false positive rate over time. Did you have to build a process to handle whitelisting requests, and if so, has the volume of those requests tapered off as expected?


Garbage in, garbage out.


   
ReplyQuote