Rae Qirui Sun
← All case studies

Carrier security · China Telecom · 6 min read

SecCat: Rebuilding a Carrier Security Product on a Core I Once Built

I inherited a just-launched SMB security product running on a partner's DNS. Eighteen months later it ran on the resolver I had built years earlier — and customers never felt the heart transplant.

SituationInherited a just-launched SMB security product built on a vendor's DNS core — my own diagnosis put real coverage of the target segment below 50%.
What I didRe-platformed the core onto the resolver I had built years earlier, without service interruption; kept the access edge deliberately partnered; grew one form factor into a family of access modes.
ResultActivatable across all 31 provincial networks, with schools, chains, hotels and government customers live — and a build-vs-buy story that came full circle.
Role
Product owner
Org
China Telecom's cybersecurity subsidiary
Time
Late 2023 – mid 2025
Product
SecCat (天翼安全猫) — secure-DNS security service riding carrier gateways
Scale
Activatable across all 31 provincial networks · a family of access modes

Context

Small businesses are the security market’s underserved majority. A tuition school, a real-estate branch, a hotel — none of them has an IT team, none will ever buy a firewall or EDR, and yet the consequences still arrive: schools get cited by regulators for students reaching inappropriate content, hotels are legally required to run internet audits on guest WiFi, and mining trojans quietly move in everywhere.

A carrier has one unfair advantage here: there is already a telecom gateway on the wall. Combine that with the lesson from my earlier work — DNS is the first step of every connection (the secure-DNS case) — and you get SecCat: security as a broadband add-on. Flip on a gateway plugin, and the site’s DNS resolution routes through a protective resolver. Phishing, botnet callbacks, mining pools and ransomware C2 die at the lookup; schools get content filtering; hotels get audit compliance. Provisioning is one click inside the carrier’s standard ordering flow, priced as a small monthly add-on to the broadband bill — tiered by customer scale, starting as low as about ¥10 a month.

To move fast, the company had launched SecCat in partnership — on a commercial vendor’s existing secure-DNS core. My own self-built resolver ran on a separate track, powering nothing. When I took ownership at the end of 2023 — taking my seat just ahead of the public launch event — my first deliverable was a candid diagnosis deck to myself. The conclusion was uncomfortable: the plugin-only scheme fit only small, simple networks; bridge-mode deployments yielded no data at all; many target customers ran home-grade gateways the plugin couldn’t reach. My summary slide put real coverage of the target segment below 50% — and noted that “the gateway advantage and the DNS advantage are not inherently linked.”

Decision 1 · Swap the heart without stopping the patient

In my year-end review I described SecCat as an iceberg product: light and simple above the waterline, with a heavy system below — carrier network infrastructure and big data. On a rented core, everything below the waterline belonged to someone else’s roadmap: intelligence quality, regional intelligence, protocol depth, integration with our own operations. For a carrier selling trust, that was strategically upside down.

So we made the core swap the year’s defining bet. I redesigned the product model and business logic around our own resolution capability, folded DNS and threat intelligence into one product flow, and shipped what a rented roadmap would never prioritize for us: dynamic intelligence construction, EDNS support, dual-stack IPv4/IPv6 resolution and protection. Four self-built DNS nodes went live, and production traffic was cut over — with service running throughout. We grew, as I wrote at the time, by stepping on every rock in the river.

The resolver at the center of it was the one from my 2022 innovation project. The build-vs-buy verdict had simply taken two years and one product to resolve.

AT TAKEOVER Access edge gateway plugin · client · hardware Vendor DNS core rented capability · rented roadmap cutover — service running AFTER Access edge — unchanged partner where we're weak Self-built resolver 4 nodes · dynamic intel · dual-stack the resolver from the 2022 innovation project, back as the heart
Swap the heart, keep the patient alive

Decision 2 · Partner where we’re weak, own where it wins

The opposite call mattered just as much. The access edge — gateway plugin firmware, a desktop client, a hardware edition — needs embedded engineering talent the division didn’t have. I kept that side deliberately partnered and made vendor management part of the product job: adaptation across the major gateway makers, and a push that got SecCat support included in newly procured business gateways by default from 2024 onward — meaning new devices arrived on customer walls already able to run us. I also evaluated a bridge-mode local-interception scheme with a niche vendor, wrote its limits down as explicitly as its promise (smaller local intelligence, provincial-by-provincial coverage) — and then shipped it deliberately as a single-province scheme rather than a national standard. Every deployment scheme got a defined lane, in writing.

Own the core where differentiation lives; partner the edge where you will never be world-class; write down which is which.

That one sentence is most of the strategy.

Decision 3 · From one form to a coverage system

The diagnosis said every deployment blind spot was a lost market segment, so the product grew from one way in to a family of them. I came to treat the integration layer as having exactly one job — however the customer’s network looks, there is a convenient way to plug into the service: a gateway plugin, a desktop client, a hardware edition, a SaaS mode that needs nothing but a DNS change at the customer’s egress (which, for the first time, let us serve customers whose broadband ran on a competitor’s network), and provincial loading schemes riding existing cloud-broadband and industry-DNS channels. I re-anchored the proposition on three value pillars — threat protection, clean internet for schools, and venue audit compliance — with a behavior-management edition following, and wired the product into the carrier’s machinery: standard small-business ICT ordering, provincial loading schemes, capability integration with the national anti-fraud platform, and a self-service layer (mini-program + web) with delegated administration fine enough that a class teacher manages one classroom while a headmaster sees the whole school.

Results

  • The core became ours: four self-built DNS nodes live, production cutover complete, dynamic intelligence and dual-stack protection shipped — a commercial product now running on the resolver from my own 0→1 project.
  • Distribution became structural: activatable across all 31 provincial networks; new centrally-procured business gateways support SecCat out of the box.
  • Real deployments, real numbers: a district tax bureau blocking 5,000+ threat lookups a month; a secondary school running per-classroom delegated protection across 60+ classes; a provincial vocational college with ~20,000 students — on a competitor’s broadband, via the SaaS mode — blocking 1,000,000+ threat lookups a month; a real-estate chain protecting 200+ branches; a metropolitan bus operator piloting 40+ stations with a 5,000-station expansion plan; hotels and serviced apartments meeting police WiFi-audit mandates with zero additional hardware.
  • My favorite single datapoint: on day one of a SaaS deployment for a government customer, our resolver blocked a single mining domain more than 4 million times — activity that host-level logging had barely registered. The DNS layer sees what host logs miss; that was the product thesis, caught on camera.
  • A complete handover in mid-2025 — my second full handover corpus in this story, honest about what remained: the self-run DNS still needed operational maturity, and provincial enablement was thinner than I wanted. Cases that contain only victories are marketing; handovers are where the truth lives.

What I learned

  • Iceberg products are won below the waterline. The visible product barely changed; the two years of work were in the resolver, the intelligence pipeline, and the procurement spec.
  • Build-buy-partner is a portfolio with revisit dates, not a verdict. We rented a core to enter the market fast, replaced it with our own to go deep, and stayed partnered at the edge indefinitely. Each was right, at its time, for its layer.
  • In SMB, distribution beats features. Getting into the default gateway procurement spec moved the product further than any capability we shipped — because the best deployment is the one that already happened.