A Fortify 24x7 brand, looking after the computers, records and back office a small firm trades on.Sign inTalk to the board
CyberSec Managed
Position 02 / Allowlist control

The crudest question in security: was this ever cleared to run here?

Most protection waits to see whether a program misbehaves, by which point it has already started. This one stops it at the door with a blunter question. Software that was never cleared for this machine simply will not run, so there is nothing to tidy afterwards, because nothing happened.

ThreatLockerDefault denyApprovals worked for you
1 circuits wired at this position
On the board1
EquipmentThreatLocker
Charged byEndpoint
ApprovalsWorked at our board

Where the cleared list comes from

Nobody hands you an empty deny list and wishes you well. The agent spends a learning spell noting what your staff genuinely open: the practice system, the accounts package, the design tools, the odd utility somebody has leaned on for a decade. That becomes the cleared list, assembled out of your firm instead of out of a template.

Updates are then the real labour. Suppliers ship new builds constantly, and a control like this will lock your front desk out of its own booking system on a Tuesday morning if nobody is following them. ThreatLocker follows the update trails; our operators work whatever is left over.

What it is like to live alongside

Frankly, for a fortnight it announces itself. Somebody will try to open a thing and be refused, and they need a route to ask about it. That route reaches an operator, and the answer comes back fast enough that people stop taking it personally.

Once settled it disappears, which is the whole point. Ringfencing then handles the second half of the job, capping what a cleared program may reach: which other programs it may launch, which folders it may open, and which destinations it may dial out to.

Tidying up after software that should never have started is expensive. Not starting it costs nothing at all.
Jacks on this position

Write ups and rates

Prices below arrive straight out of billing. Whatever gets patched in waits on the list while you read on.

Fortify-ZeroTrustWrite up

Execution Control

ThreatLocker, deciding what may start at all

Detection asks whether a program is misbehaving, which means it already started. This asks a cruder question at the door. Was this thing ever cleared for this machine. If not, it never runs, and there is no mess to mop up because nothing occurred.

  • A learning spell assembles the cleared list out of the software your staff genuinely use.
  • Vendor updates get followed, so a Tuesday release does not shut the front desk out.
  • Ringfencing limits what a cleared program may touch once it is up and running.
Patched toThreatLocker
Listens onEvery program attempting to start on an enrolled machine
Line heldThe cleared list, kept current as your suppliers push updates
Answered byFortify 24x7 operators, who work the approval and elevation queue
Traced byOne endpoint, charged monthly
Readingper endpoint
payable in advance, monthly
QTY
Plain limits

Calls we cannot take

This position earns its keep and it has edges. Set out below is the ground these circuits leave uncovered, plainly enough to plan around.

  • Not antivirus, and no substitute for the detection position. Allowlisting halts whatever was never cleared. It passes no judgement on the conduct of software you did clear, which is precisely the job of the detection circuits. The pair get bought together for that reason.
  • Cleared software can still be misused. Your accounts package is cleared. A person entitled to use it can still pay money into the wrong account. This control has nothing whatever to say about that.
  • A decision maker at your end is required. We work the approval queue, but a genuinely new business application needs a person at your end who can say yes to it. Lacking that named person, requests sit and tempers fray.
  • What happens in a browser is untouched. Card details typed into a convincing counterfeit page involve no program starting on the machine whatsoever. Filtering and mailbox protection are the controls bearing on that.
  • Unmanaged machines sit outside it. The circuit applies to endpoints carrying the agent. Anything unenrolled goes on running whatever it fancies, exactly as it did before you bought a thing.
NOTICE

Heads up: card statements show FORTIFY 24X7 - CyberSec Managed is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.