One key, one invoice, one desk. A Fortify 24x7 brand.Account sign inReach an engineer
Iconic IT Innovations
Plate 02 / Execution control

The safest program on the estate is the one that never got to start.

Detection argues about what a program did once it was running. Execution control has a much shorter argument: it did not run, because nobody had ever approved it. On the hardware where an incident would genuinely hurt, that is the cheaper of the two conversations to be having.

ThreatLockerRefuse unless permittedRingfencingElevation at our desk
1 lines / ThreatLocker
Lines on this plate1
PlatformThreatLocker
Measured inEndpoint
ElevationWorked by Fortify 24x7

Why refusing by default is gentler than it sounds

The objection never varies and it is a reasonable one: a permitted list sounds like two weeks of people unable to do their jobs. The watching period is the way through. ThreatLocker observes what genuinely runs on the hardware you nominate, assembles the baseline out of that observation, and only then begins refusing. What ends up permitted is the software your business is actually using, not a list somebody typed up from memory in a meeting.

After that, two things keep it liveable. Vendor releases are followed, so a permitted application does not become a refused one overnight when its publisher ships an update. And elevation requests come to Fortify 24x7 rather than piling up with a user who will eventually go and find a way around the whole arrangement.

Switch it on everywhere in a week and you will switch it off in the second week. Start with the forty machines that matter.

Where to point it first

Organisations that switch this on everywhere inside a week tend to switch it off again inside the second one. The ones that succeed start where the consequences are concentrated: whatever touches the finance system, the hosts that talk to the ERP, jump boxes, the controllers driving a line, and the dozen or so desks holding drawings, bids or contracts.

Ringfencing is the underrated half. Permission to run is not permission to roam. Fencing a tool into the files it needs, the programs it may start and the addresses it may reach is what keeps a perfectly legitimate utility from being borrowed for an entirely different purpose.

Lines on this plate

Detail and rates

Every rate below is fetched from billing the moment this page opens. Whatever gets marked waits in the schedule; reading on costs you nothing.

Fortify-ZeroTrustSign spec

Execution Control

Permitted lists, ringfencing and elevation, on ThreatLocker

Deny by default, done properly. The machine runs what you approved and turns down everything else, including the clever payload that arrived inside an archive nobody meant to open.

  • A watching period assembles the permitted list out of software your people truly use.
  • Releases are followed, so a vendor update does not lock a department out at breakfast.
  • Ringfencing fences a permitted tool into the files, programs and addresses it needs.
PlatformThreatLocker
PostureRefuse unless permitted
Watching periodA monitored spell builds the baseline before enforcement starts
ReleasesVendor updates followed so permitted software keeps working
ElevationRequests are worked by Fortify 24x7, never dumped on the user
Measured inEndpoint, each month
Readingper endpoint
charged ahead of each month
QTY
Where this plate stops

The honest edge of these 1 lines.

Written down in advance, so the question of what else the estate needs gets asked now and not in the middle of something.

  • It governs what runs, not why somebody ran it. A permitted application, misused by a permitted person, remains permitted. Execution control holds no opinion about someone with genuine access doing something unwise inside software they are entitled to open.
  • Expect a bedding in period, and expect us to say so. Observation takes time and the opening weeks of refusal generate requests. We work them at our desk, but the effort is real and it belongs in your plan rather than arriving as a surprise in week three.
  • It does not excuse you from updating anything. A weakness inside software you permitted is still a weakness. A permitted list narrows what may execute; it cannot make an out of date application safe. That is why route four exists and why the two are usually bought together.
  • Hardware outside the deployment is outside the policy. This line reaches endpoints carrying the agent. A contractor laptop, or a home desktop nobody ever enrolled, is untouched by any rule you write here, however careful you were.
  • It is not a replacement for watching. Refusing by default and weighing up behaviour answer two different questions. An estate running one without the other has chosen between knowing what happened and preventing it, when on the hardware that matters the sensible answer is to have both.
BEFORE YOU PAY

Heads up: card statements show FORTIFY 24X7 - Iconic IT Innovations is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.