Toronto's Iconic Roy Thomson Hall Secures Public Wi-Fi With Control D

Read how Control D secures guest Wi-Fi and internal networks for Massey Hall & Roy Thomson Hall, two of Toronto's iconic performing arts venues.

· 6 min read
Toronto's Iconic Roy Thomson Hall Secures Public Wi-Fi With Control D

About Massey Hall & Roy Thomson Hall

Massey Hall and Roy Thomson Hall are two of Toronto’s most iconic performing arts venues, hosting concerts, theatrical productions, and a wide range of live events that attract millions of patrons each year.

Behind the scenes, their IT team is responsible for ensuring seamless connectivity and security across both venues, managing a high-traffic public Wi-Fi network and a hybrid workforce at each location.

We spoke with Neil Bowen, IT Manager at The Corporation of Massey Hall & Roy Thomson Hall, to learn how Control D became a key part of their cybersecurity and DNS management strategy.

The Problem

Before implementing Control D, Neil and his team were relying on built-in DNS and web filtering services bundled with their FortiGate firewall. But when the annual renewal came up, Neil was taken aback by the price. “The cost of the DNS and web filter subscription was outrageous,” he said. 

While cost was the tipping point, it wasn’t the only issue. The existing system also made their job harder than it needed to be. Internally, they experienced:

  • Accessing logs and filtering data was overly complex.
  • Clunky management where blocking and unblocking domains required multiple steps and wasn’t intuitive.
  • Limited visibility and insight into what users were doing on the network.

Externally, the guest Wi-Fi lacked proper filtering altogether, opening the door for malware and phishing threats, network abuse, and heavy bandwidth usage.

These limitations were frustrating for the IT team and prompted them to reevaluate their current setup. They needed a solution that could:

  • Secure the public Wi-Fi network without degrading performance or user experience.
  • Simplify reporting and management across both venues.
  • Provide visibility into DNS activity across internal and guest networks.
  • Work seamlessly with their hybrid workforce.
  • Reduce operational costs.

The Solution

With their existing contract coming up for renewal, Bowen saw an opportunity to explore Control D. Having used it personally, he was already a fan:

"I was aware of your business launch and had been thinking, even as our old system hadn’t expired yet, that I would like to try it… the simplicity of Control D was a big attractor."

Massey Hall & Roy Thomson Hall implemented Control D to replace their previous DNS filtering solution. From the start, Bowen found the transition smooth: "It was just working so well for us. There was no reason to try other [solutions] at that point."

Frictionless Filtering for Guest Wi-Fi

Protecting the public Wi-Fi network across both venues was the most urgent – and surprisingly most straightforward – part of the deployment: “Deploying for the guest Wi-Fi was easier, even, than deploying for our internal network.”

Since guests are transient users, the team didn’t need granular identity tracking. Instead, they simply applied a single Control D profile to their guest network firewall, which they configured in just a few small steps.

“The categories and features built in make it that much easier. With the flip of a toggle, we were instantly blocking torrents, file hosting sites, crypto miners, phishing sites, and malware sites, without having to manually find and manage block lists.”

This helped protect users – many of whom didn’t even realize they were being protected – while also preventing the misuse of bandwidth. “We want our guests to have a good Internet experience and not be bogged down with people torrenting or crypto mining on our network,” Neil added.

Streamlined Protection for a Hybrid Workforce

Internally, the Control D rollout began with DNS forwarders and later transitioned to direct device-level deployment via Microsoft Intune. This allowed for consistent policy enforcement across on-site and remote users. 

"It’s actually better for us to have it installed on the devices themselves because that way we can still control access to dangerous sites, even when users are working remotely," Bowen explained.

Enhanced Visibility and Shadow IT Control

One of the biggest game-changers was the increased visibility Control D offered into real-time DNS activity. “We’re not trying to invade privacy," Bowen clarified. "We’re just trying to use it as a cybersecurity tool to prevent access to malicious sites." 

With Control D’s clean, real-time analytics and daily email reports, the team quickly discovered unexpected activity on their guest network: “Blocking P2P and crypto had a big impact. They are constantly the most blocked services on the guest network, which we didn’t know.”

“Whereas pulling logs from our previous service was complicated and time-consuming, the analytics in Control D are clean and easy to access… The visibility into the traffic being accessed on our guest network has been a real eye-opener.”

On their internal network, Control D revealed apps, tools, and services that departments were using without IT approval, known as “shadow IT,” which is a major security concern. 

“Now we know they’re using [unauthorized web apps], we can talk to the department, get access to the app, and make sure it's valid and vetted for security – or shut it down if we need to.”

Intuitive Management and Prebuilt Filters

Control D’s web interface made blocking, unblocking, and organizing domains significantly easier. Folder groups and extensive prebuilt filter libraries helped streamline operations.

“The breadth of prebuilt filters has been great… We don’t have to figure out all the domains Microsoft or Amazon is using.”

Control D’s flexibility also proved valuable in handling content filtering for artists’ websites. "Because we’re a performing arts center, we get a lot of artist websites that get blocked as marketing sites," Bowen noted. With Control D, his team could quickly adjust configurations to prevent unnecessary disruptions.

One Platform, Full Control

The ability to manage both internal and guest traffic across two venues from one cloud-based dashboard was a massive improvement.

“Having control and visibility all in one place – for two locations running both internal and guest networks – has been an immense time saver. We literally have one place to go (accessible from anywhere) where we can get full insights on the Internet traffic across our whole organization.”

Seamless Integration with Zero End-User Disruption

Control D ran silently in the background. Most users didn’t even realize anything had changed – unless they ran into a newly blocked site. From an IT perspective, the platform was invisible to users but gave admins complete control.

“It’s been virtually invisible from the end-user point of view, and with tons of visibility from the admin point of view. It’s that great hybrid.”

Hands-On Support When It Mattered

When Neil encountered a few challenges, Control D’s team was immediately responsive, bringing in the right people during a live call to resolve the issues in real time.

“The account manager reached out to somebody else on your team and then they joined the call… We worked through it right there in the span of 45 minutes.”

The Results

Since switching to Control D, Massey Hall & Roy Thomson Hall have seen significant improvements in efficiency and security. 

  • Faster, Safer Guest Wi-Fi: Performance for guests improved significantly, with zero complaints since the switch. “Service has improved dramatically in terms of speed and reliability for guests… Since implementing [Control D], we have had zero complaints about speed or availability of guest Wi-Fi service.”
  • Effortless Deployment: There was no user friction during rollout, and it has been a smooth process from start to finish. "People don’t even know we’ve pushed it out to their system," Bowen said. "For the benefit it’s providing, it’s been virtually seamless. We haven’t had any pushback.”
  • Simplified Management: Control D made it easy to manage DNS policies without hunting down domains or building rules from scratch. "The ability to create a group of blocks or unblocks as a folder — that’s been helpful for us."
  • Surprising Insights: With Control D, the team receives real-time analytics and daily summary emails, revealing usage patterns that were previously hidden. “We didn’t realize just how many people were using TikTok or Snapchat... It’s not about monitoring employees – it’s just valuable insight that we didn’t have before.”
  • Cost Reduction: Replacing FortiGate’s bundled filtering solution not only improved usability but also significantly reduced annual costs.

Neil Bowen describes the experience with Control D as overwhelmingly positive: “The implementation was straightforward, the reporting is much clearer, and the service has been seamless. The visibility we now have into our network is invaluable.”

Control D has quickly become a critical part of the cybersecurity stack for two of Toronto’s most iconic venues, proving that enterprise-grade DNS filtering can be simple, effective, and user-friendly.

“It’s a really great product. The analytics, cost, functionality, and ease of the interface... I would definitely recommend it without reservation.”

If you’re looking for a simple, effective, and scalable cybersecurity solution for your business, explore how Control D can work for you.

Blocks threats, unwanted content, and ads on all devices within minutes

Secure, Filter, and Control Your Network

Control D is a modern and customizable DNS service that blocks threats, unwanted content and ads - on all devices. Onboard in minutes, and forget about it.

Deploy Control D in minutes on your device fleet using any RMM

Block malware, harmful content, trackers and ads in seconds

Go beyond blocking with privacy features