A Fortify 24x7 brand. Protective coverage for small and medium businesses across North America.Client portalContact
CyberThreat Help
02RUNG
ThreatLocker · default deny · approvals staffed around the clock

Execution control

The rung that decides in advance. Your machines run the programs you approved and refuse the rest, so unfamiliar software never gets the chance to be interesting.

01The threat

Nothing said no.

Most malicious software succeeds for a dull reason: it was allowed to start. It arrived in an attachment or a download, somebody double clicked it, and no part of the machine had any opinion about whether that program should be running at all.

Detection answers the question after the fact, and answers it well. Allowlisting removes the question. If a program is not on your list, it does not run, and there is nothing to investigate.

02The method

A list, kept current by us.

Deployment starts in monitoring mode. For a period we watch what your business genuinely runs and build the first list from that, rather than handing you a blank policy and wishing you luck.

Once enforcement is on, vendor updates are tracked automatically so a routine patch does not turn into a blocked morning. Anything genuinely new comes to our desk as a request, and it is worked by people on every shift.

03The extras

Approved does not mean unlimited.

Being on the list controls whether a program runs. It does not have to control everything a program may then do, and this rung lets you go further where it matters.

An approved application can also be fenced in. Tell it which programs it may start, which files it may open, and which network destinations remain available to it. Fencing of that sort is what keeps an ordinary office program from becoming the delivery van for something worse.

04The cost

The friction is real. Here it is.

Anyone calling this control free has not deployed one. Once the learning period closes, fresh software has to be approved before it will start. Our desk is staffed, so the wait is normally a matter of minutes, but the step itself is new to your week.

Firms that install software constantly notice it most. Firms whose machines run a short, settled list of programs hardly register it, and those happen to be the machines on which this rung repays its rate fastest. Many customers settle on a tight policy for finance and administration hardware, with something gentler everywhere else.

Lines on this rung

1 line · rates per unit, per month
Fortify-ZeroTrustManual entry

Application Allowlisting

ThreatLocker · default deny · approvals staffed around the clock

Your machines run the software you approved and refuse the rest. Not a scanner deciding whether a program looks bad: a list deciding whether it is allowed at all. Requests to add something come to our desk, so nobody waits on a policy.

  • A learning period builds the first list from what you already run.
  • Updates from software vendors are followed automatically, so a routine patch is not a blocked morning.
  • Approved programs can be limited in what they launch, read, and reach.
  • Requests reach staffed people, normally answered in minutes.
ModelDeny by default. What you approved starts, and nothing else does
BaselineLearned from your own machines during a monitoring period
UpdatesVendor releases tracked so approvals stay current
BoundariesCaps on what an approved program may spawn, open, and dial out to
ApprovalsHandled at our staffed desk, all day and all night
Priced byEndpoint, monthly
Loading per endpoint
monthly, taken in advance
QTY

Where this rung stops

Allowlisting rules on which code may run. It holds no view at all on the choices a person makes inside a program that was already approved.

  • An approved browser, a convincing page, and somebody typing their password into it: no program had to start for any of that to happen. Filtering on rung 04 and mail defence on rung 03 are what cover it.
  • Extensions added from a browser's own store do not arrive as unapproved binaries, so they pass. Policy on extensions is a rule we help you draft rather than a line to buy.
  • The learning period is a genuine deployment cost. Budget time for it instead of meeting it by surprise.
  • This line covers managed endpoints only. Machines outside your policy, including personal hardware, are not in scope.
  • A live break in is worked by the operations team through support, not by adding a subscription line. Say what you are seeing and we will tell you what happens next.

One more thing, stated where you can see it before you buy. Everything on this page is protective coverage bought in advance. It is not an emergency incident response retainer, and it does not put a responder on your site tomorrow because you subscribed today. An engagement of that kind is arranged directly with the Fortify 24x7 operations team. If something is under way as you read this, the quickest route to us is support@cyberthreat.help, or a case raised from your client portal.

Heads up: card statements show FORTIFY 24X7 - CyberThreat Help is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.