Rae Qirui Sun
← All case studies

Carrier security · China Telecom · 7 min read

SecCat: Rebuilding a Carrier Security Product on a Core I Once Built

I inherited a just-launched SMB security product running on a partner's DNS. Eighteen months later it ran on the resolver I had built years earlier — and customers never felt the heart transplant.

SituationInherited a just-launched SMB security product built on a vendor's DNS core — my own diagnosis put real coverage of the target segment below 50%.
What I didRe-platformed the core onto the resolver I had built years earlier, without service interruption; kept the access edge deliberately partnered; grew one form factor into a family of access modes.
ResultActivatable across all 31 provincial networks, with schools, chains, hotels and government customers live — and a build-vs-buy story that came full circle.
Role
Product owner
Org
China Telecom's cybersecurity subsidiary
Time
Late 2023 – mid 2025
Product
SecCat (天翼安全猫) — secure-DNS security service riding carrier gateways
Scale
Activatable across all 31 provincial networks · a family of access modes

The patient

Small businesses are the security market’s underserved majority. A tuition school, a real-estate branch, a hotel — none of them has an IT team, none will ever buy a firewall or EDR, and yet the consequences still arrive: schools get cited by regulators for students reaching inappropriate content, hotels are legally required to run internet audits on guest WiFi, and mining trojans quietly move in everywhere.

A carrier has one unfair advantage here: there is already a telecom gateway on the wall. Combine that with the lesson from my earlier work — DNS is the first step of every connection (the secure-DNS case) — and you get SecCat: security as a broadband add-on. Flip on a gateway plugin, and the site’s DNS resolution routes through a protective resolver. Phishing, botnet callbacks, mining pools and ransomware C2 die at the lookup; schools get content filtering; hotels get audit compliance. Provisioning is one click inside the carrier’s standard ordering flow, priced as a small monthly add-on to the broadband bill — tiered by customer scale, starting as low as about ¥10 a month.

The diagnosis nobody asked for

To move fast, the company had launched SecCat in partnership — on a commercial vendor’s existing secure-DNS core. My own self-built resolver ran on a separate track, powering nothing. I took my seat at the end of 2023, just ahead of the public launch event — which is to say, I inherited the product at the exact moment it became too public to quietly fix.

My first deliverable was a diagnosis deck addressed to myself, and it flattered no one. The plugin-only scheme fit only small, simple networks. Bridge-mode deployments yielded no data at all. Many target customers ran home-grade gateways the plugin couldn’t reach. The summary slide put real coverage of the target segment below 50%, and closed on the line the next two years would answer: “the gateway advantage and the DNS advantage are not inherently linked.” Linking them was the job.

In my year-end review I described SecCat as an iceberg product — light and simple above the waterline, with a heavy system below: carrier network infrastructure and big data. On a rented core, everything below the waterline belonged to someone else’s roadmap: intelligence quality, regional intelligence, protocol depth, integration with our own operations. For a carrier selling trust, that was strategically upside down.

The transplant

So the core swap became the year’s defining bet — a heart transplant on a patient that had just been wheeled, waving, past the press.

The new heart wasn’t new. It was the resolver from my 2022 innovation project, built as a bet that a carrier should own exactly this capability, then left running on a separate track. I redesigned the product model and business logic around our own resolution capability, folded DNS and threat intelligence into one product flow, and shipped what a rented roadmap would never prioritize for us: dynamic intelligence construction, EDNS support, dual-stack IPv4/IPv6 resolution and protection. Four self-built DNS nodes went live, and production traffic was cut over — with service running throughout. Customers never felt the switch. We grew, as I wrote at the time, by stepping on every rock in the river.

The build-vs-buy verdict had simply taken two years and one product to resolve.

AT TAKEOVER Access edge gateway plugin · client · hardware Vendor DNS core rented capability · rented roadmap cutover — service running AFTER Access edge — unchanged partner where we're weak Self-built resolver 4 nodes · dynamic intel · dual-stack the resolver from the 2022 innovation project, back as the heart
Swap the heart, keep the patient alive

What I refused to build

The opposite call mattered just as much. The access edge — gateway plugin firmware, a desktop client, a hardware edition — needs embedded engineering talent the division didn’t have, and no eighteen months of heroics would change that. I kept that side deliberately partnered and made vendor management part of the product job: adaptation across the major gateway makers, and a push that got SecCat support included in newly procured business gateways by default from 2024 onward — meaning new devices arrived on customer walls already able to run us. When a niche vendor pitched a bridge-mode local-interception scheme, I wrote its limits down as explicitly as its promise — smaller local intelligence, provincial-by-provincial coverage — and then shipped it deliberately as a single-province scheme, not a national standard. Every deployment scheme got a defined lane, in writing.

Own the core where differentiation lives; partner the edge where you will never be world-class; write down which is which.

That one sentence is most of the strategy.

Every network gets a door

The diagnosis had said it plainly: every deployment blind spot was a lost market segment. So the product grew from one way in to a family of them. I came to treat the integration layer as having exactly one job — however the customer’s network looks, there is a convenient way to plug into the service. A gateway plugin. A desktop client. A hardware edition. A SaaS mode that needs nothing but a DNS change at the customer’s egress — which, for the first time, let us serve customers whose broadband ran on a competitor’s network. Provincial loading schemes riding existing cloud-broadband and industry-DNS channels.

Around those doors, I re-anchored the proposition on three value pillars — threat protection, clean internet for schools, and venue audit compliance — with a behavior-management edition following, and wired the product into the carrier’s machinery: standard small-business ICT ordering, capability integration with the national anti-fraud platform, and a self-service layer (mini-program + web) with delegated administration fine enough that a class teacher manages one classroom while a headmaster sees the whole school.

The ledger

Eighteen months of surgery, in the account book:

  • The core became ours — four self-built DNS nodes live, production cutover complete, dynamic intelligence and dual-stack protection shipped: a commercial product now running on the resolver from my own 0→1 project.
  • Distribution became structural — activatable across all 31 provincial networks; new centrally-procured business gateways support SecCat out of the box.
  • Real deployments, real numbers — a district tax bureau blocking 5,000+ threat lookups a month; a secondary school running per-classroom delegated protection across 60+ classes; a provincial vocational college with ~20,000 students — on a competitor’s broadband, via the SaaS mode — blocking 1,000,000+ threat lookups a month; a real-estate chain protecting 200+ branches; a metropolitan bus operator piloting 40+ stations with a 5,000-station expansion plan; hotels and serviced apartments meeting police WiFi-audit mandates with zero additional hardware.

My favorite single datapoint arrived on day one of a SaaS deployment for a government customer: the resolver blocked one mining domain more than 4 million times — activity that host-level logging had barely registered. The DNS layer sees what host logs miss. That was the product thesis, caught on camera.

I handed the product over in mid-2025 — my second full handover corpus in this story, honest about what remained: the self-run DNS still needed operational maturity, and provincial enablement was thinner than I wanted. Cases that contain only victories are marketing; handovers are where the truth lives.

Below the waterline

The visible product barely changed in two years; the work lived in the resolver, the intelligence pipeline, and a procurement spec — iceberg products are won below the waterline. Build-buy-partner turned out to be a portfolio with revisit dates, not a verdict: rent to enter fast, build to go deep, partner where you’ll never be world-class — each right, at its time, for its layer. And in this market, distribution beats features. Getting into the default gateway procurement spec moved the product further than any capability we shipped, because the best deployment is the one that already happened.