A Fortify 24x7 brand. Grown up security platforms, sold the way software used to be sold.Client sign inMail an engineer
Cyb3rs3cur1ty
Module 02 // Execution control

The shortest security policy ever written: unlisted software does not get to run.

Antivirus spends its life guessing which of several million unknown programs are hostile. Allowlisting turns the question upside down and asks a much easier one: is this on the list of software this company actually uses? Everything else gets stopped and sent to us for a decision.

ThreatLockerAllowlistingRingfencing
1 line / default deny / learning period included
Lines here1
EngineThreatLocker
Counted byEndpoint
Who approvesHandled at our desk

How a default deny rollout avoids becoming a nightmare

Allowlisting has a reputation, and the reputation comes from people switching it on cold and then spending a fortnight approving Notepad. That is not how this runs. The agent spends its first weeks learning, taking an inventory of what genuinely executes on your machines and turning that into the opening policy. Only when the picture looks like your business does anything start getting blocked.

From then on the approvals come to us. Somebody installs a new design tool, the ask arrives at our desk, and an engineer works out what it is before letting it through. Most requests are dull and get cleared quickly. The interesting ones are exactly the ones you were hoping to stop.

An easier question tends to get a better answer.

Ringfencing, the half that nobody talks about

Allowlisting decides whether a program may run at all. Ringfencing decides what it may get up to afterwards. An approved spreadsheet program has no business launching a scripting engine, and a scripting engine has no business talking to a server three time zones away. Fencing those relationships closes off most of the tricks that rely on software you installed on purpose.

Elevation control belongs here too. Somebody who needs administrator rights for one specific task can have them for that task, on that application, without carrying a permanent administrator account around all day long.

Lines on this module

Specifications and rates

Every rate below arrives live from billing. Anything you pick up drops into the inventory panel and sits there quietly.

Fortify-ZeroTrustSpec

Execution Control

ThreatLocker allowlisting, ringfencing and elevation control

Nothing starts on a machine unless the list already knows about it. Software you approved runs exactly as normal. Everything else stops at the door and raises a request.

  • The opening policy is assembled from software that already runs here.
  • Ringfencing draws the boundary: which programs it may start, what it may open, and where it may phone.
  • Requests to approve something new land at our desk, not on your list.
EngineThreatLocker
BoxesEndpoints and servers running Windows or macOS
Order of playLearning period first, enforcement afterwards
Who approvesHandled by Fortify 24x7 engineers
Thrown inRingfencing and elevation control
Counted byEndpoint, each month
Loadingper endpoint
billed each month, in advance
QTY
Honest scope

What sits in the box, and what does not

Default deny is the strongest control on this website and the one with the sharpest edges. Here is exactly what it covers.

IN THE BOX

  • A policy built from your own inventory during the learning period, instead of a generic template written for somebody else.
  • Blocking of unapproved software including things that arrived five minutes ago and have no reputation anywhere yet.
  • Ringfencing rules governing what approved software may launch, open and reach out to.
  • Elevation for a single task so people stop carrying administrator rights around all day.
  • Approval handling at our desk so a request does not sit unread in your inbox.

NOT IN THE BOX

  • Detection and response. This module stops software from running. Watching behavior and investigating cases is a different module entirely.
  • Unmanaged personal machines. The policy applies to enrolled devices. A home laptop outside the fleet is outside this line.
  • Enforcement on day one. Skipping the learning period is how allowlisting projects fail, so it does not get skipped here.
  • Web content filtering. Controlling which sites a browser may reach lives over in the device fleet module.
  • Automatic approval of anything. A request that lands at two in the morning still gets read by a person, and a person is allowed to say no.
NOTE 01

Heads up: card statements show FORTIFY 24X7 - Cyb3rs3cur1ty is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.