Nothing said no.
Most malicious software succeeds for a dull reason: it was allowed to start. It arrived in an attachment or a download, somebody double clicked it, and no part of the machine had any opinion about whether that program should be running at all.
Detection answers the question after the fact, and answers it well. Allowlisting removes the question. If a program is not on your list, it does not run, and there is nothing to investigate.
A list, kept current by us.
Deployment starts in monitoring mode. For a period we watch what your business genuinely runs and build the first list from that, rather than handing you a blank policy and wishing you luck.
Once enforcement is on, vendor updates are tracked automatically so a routine patch does not turn into a blocked morning. Anything genuinely new comes to our desk as a request, and it is worked by people on every shift.
Approved does not mean unlimited.
Being on the list controls whether a program runs. It does not have to control everything a program may then do, and this rung lets you go further where it matters.
An approved application can also be fenced in. Tell it which programs it may start, which files it may open, and which network destinations remain available to it. Fencing of that sort is what keeps an ordinary office program from becoming the delivery van for something worse.
The friction is real. Here it is.
Anyone calling this control free has not deployed one. Once the learning period closes, fresh software has to be approved before it will start. Our desk is staffed, so the wait is normally a matter of minutes, but the step itself is new to your week.
Firms that install software constantly notice it most. Firms whose machines run a short, settled list of programs hardly register it, and those happen to be the machines on which this rung repays its rate fastest. Many customers settle on a tight policy for finance and administration hardware, with something gentler everywhere else.
Lines on this rung
1 line · rates per unit, per monthApplication Allowlisting
Your machines run the software you approved and refuse the rest. Not a scanner deciding whether a program looks bad: a list deciding whether it is allowed at all. Requests to add something come to our desk, so nobody waits on a policy.
- A learning period builds the first list from what you already run.
- Updates from software vendors are followed automatically, so a routine patch is not a blocked morning.
- Approved programs can be limited in what they launch, read, and reach.
- Requests reach staffed people, normally answered in minutes.
| Model | Deny by default. What you approved starts, and nothing else does |
|---|---|
| Baseline | Learned from your own machines during a monitoring period |
| Updates | Vendor releases tracked so approvals stay current |
| Boundaries | Caps on what an approved program may spawn, open, and dial out to |
| Approvals | Handled at our staffed desk, all day and all night |
| Priced by | Endpoint, monthly |
monthly, taken in advance QTY
Where this rung stops
Allowlisting rules on which code may run. It holds no view at all on the choices a person makes inside a program that was already approved.
- An approved browser, a convincing page, and somebody typing their password into it: no program had to start for any of that to happen. Filtering on rung 04 and mail defence on rung 03 are what cover it.
- Extensions added from a browser's own store do not arrive as unapproved binaries, so they pass. Policy on extensions is a rule we help you draft rather than a line to buy.
- The learning period is a genuine deployment cost. Budget time for it instead of meeting it by surprise.
- This line covers managed endpoints only. Machines outside your policy, including personal hardware, are not in scope.
- A live break in is worked by the operations team through support, not by adding a subscription line. Say what you are seeing and we will tell you what happens next.
One more thing, stated where you can see it before you buy. Everything on this page is protective coverage bought in advance. It is not an emergency incident response retainer, and it does not put a responder on your site tomorrow because you subscribed today. An engagement of that kind is arranged directly with the Fortify 24x7 operations team. If something is under way as you read this, the quickest route to us is support@cyberthreat.help, or a case raised from your client portal.