A Fortify 24x7 brand. Gauges, hourly readings and a watch desk kept for smaller firms.Client sign inReach the desk
CyberThreat Management
Front 02 / Execution control

The shutter goes down before the weather gets in.

Everything else here reads conditions and reports them. This line is a different kind of thing. What may run on a machine gets settled in advance and the rest is refused, which takes a whole category of trouble off the board instead of writing it up afterwards.

ThreatLockerDefault denyObservation period first
One line. Approve what runs, refuse the rest.
Lines posted1
Read byThreatLocker
UnitEndpoint
Set upObservation first, enforcement after

Why a refusal beats a reading

Pressure falling is what a gauge tells you. Rain kept off the stock is what a shutter does. Both earn their keep, and neither substitutes for the other. Execution control is the shutter. Anything absent from the approved list will not start, whether it came in an attachment, off a memory stick, or down from a website that looked perfectly ordinary.

Severe, until you see how the list gets built. Observation mode runs first, across a few weeks of ordinary trading, watching what staff genuinely open, and the approved list falls out of that rather than out of a template. Enforcement follows, with a request route for whatever those weeks missed.

Pressure falling is what a gauge tells you. Rain kept off the stock is what a shutter does.

Ringfencing, which is the quieter half

Approving an application does not amount to trusting it everywhere. Ringfencing states which files a program may open, plus the other programs it may launch, plus the destinations it may talk to. A reader with no business starting a scripting engine is told once, and quietly stops being a way in.

Vendor updates get handled here as well. Self updating software is tracked, so a genuine new release does not shut the counter staff out mid morning while an approval waits.

Lines on this front

Line records and rates

Every rate here is drawn from billing as the page renders. Anything you log stays in the observation log while reading continues.

Fortify-ZeroTrustLine record

Execution Control

ThreatLocker, default deny after an observation period

A shutter, not a gauge. Software nobody approved never gets to run, which lifts a whole class of trouble off the board instead of watching it turn up.

  • Observation runs for a period, and the approved list assembles itself from whatever software your staff genuinely open.
  • Updates from a vendor get tracked, so no release shuts the counter staff out mid morning.
  • Ringfencing limits which files, which programs and which destinations an approved application may touch.
Observed atEvery program launch across the machines you enrol
ForecastsNothing. Unapproved software gets refused here, not predicted
ArchivedAn approval list and every refusal, readable for review at any hour
Issued byThreatLocker
Confirmed atThe Fortify 24x7 desk, which reviews approval requests as they land
Readingper endpoint
charged up front, each month
QTY
Honest scope

Where this front stops

No stronger single control appears anywhere on this site, and edges remain even so. Worth knowing them before the card comes out.

  • It refuses software, not decisions. Somebody genuinely permitted to open a file and forward it is doing something the approved list holds no opinion about. That sits with data exposure, and with procedure you write.
  • The observation period is real work. Three days of observation buys months of irritation. We would sooner run it properly and switch enforcement on later than sell a fast deployment that gets turned off in week three.
  • Approval requests need somebody to answer them. Our desk works them, and a genuine wait exists while a request gets checked. Default deny costs that, honestly stated, because pretending otherwise makes a poor beginning.
  • Mail and cloud accounts are not read by this line. This line lives at the machine. Mail belongs to another front, and so does anything happening entirely inside a browser tab.
  • Unenrolled machines are unaffected. Enrol nothing and nothing changes. Any personal laptop kept off enrolment keeps running whatever it fancies. Cover follows enrolment here, exactly as everywhere else on this site.
NOTICE 01

Heads up: card statements show FORTIFY 24X7 - CyberThreat Management is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.