@alice @catsalad @Em0nM4stodon I've gone a similar route where I can. Running your own DNS so you can't even accidentally send traffic is a big one.
I'm slowly getting some of my business clients to buy into this approach. If employees want that stuff, they have personal devices for it.
A simple first step for businesses is setting upstream DNS to https://www.joindns4.eu/ to start them on their journey