Run by Fortify 24x7. Cover for the machines, the mailboxes and the books a small business trades on.Sign inAsk us something
ServiceShield IT
1-4 Block section

Software you approved runs. The rest waits on somebody saying yes.

Most controls end up arguing about whether one particular thing is bad. Allowlisting will not have the argument. What you approved runs on the machine and nothing else does, which converts an enormous category of trouble into a request sitting in a queue.

ThreatLockerDefault denyRingfencing
Levers here1
PlantThreatLocker
UnitOne endpoint
DeskFortify 24x7, at any hour

Why a default deny earns its keep

Antivirus wants to know whether a file looks bad. Allowlisting wants to know whether it was approved, an easier question carrying a far steadier answer. An unrecognised script, an installer somebody downloaded, a document quietly attempting to start something: one rule stops the lot, and nothing had to be recognised beforehand.

The fair objection is that all of this sounds obstructive. It is, for a fortnight or so, which is precisely why a learning spell exists. The agent notes down whatever your people genuinely run, assembles a list out of that, and then holds it.

Allowlisting will not argue about whether one particular file looks bad.

When somebody needs something new

A request lands at the Fortify 24x7 desk rather than in a folder nobody opens. Updates known to come from a vendor are followed on their own, so a routine patch to accounting software does not lock everybody out on a Tuesday while people go hunting for an administrator.

Ringfencing carries further than a list. An application permitted to run is not thereby permitted to reach every file, start every child process and speak to every address. You draw the boundary; the boundary gets held.

2-1 Levers in what may run

What each one does, and what it costs

Rates are lifted live from billing while this page loads. Whatever you send to the sheet sits waiting while you read on.

Fortify-ZeroTrustLever

Execution Control

ThreatLocker: allowlisting, plus ringfencing, plus elevation control

Default deny, on whichever machines would sting most to lose. Software you approved runs. Everything else waits on somebody saying yes, which is a dull sentence describing a control that stops a startling share of what walks past everything else.

  • A learning spell assembles the allowlist out of software your staff truly use.
  • Updates known to come from vendors get followed, so a routine patch will not shut the counter out.
  • Ringfencing rules on which files, which spawned processes, and which destinations an application may reach.
  • Elevation requests reach the desk Fortify 24x7 staffs instead of sitting unread.
Cleared forEndpoints running Windows or macOS
ProtectsWhatever is permitted to execute on the machine in the first place
Held untilA learning spell has assembled the list from genuine working use
Signalled byThreatLocker
Confirmed byA trail of requests naming every approval and whoever granted it
Readingper endpoint
monthly, settled ahead of the period
QTY
6 Obstruction danger

Where cover ends in this section

Default deny makes a strong control, and a narrow one. Set out below is exactly what a single lever leaves alone, so that nobody buys it expecting something else.

  • Execution is all it governs. Somebody signing in on a stolen password and reading mail in a browser has executed nothing out of the ordinary. Catching that belongs to the mailbox and detection sections. This lever will see none of it.
  • Approved software is still misusable. Tools your staff need are on the list because they need them. A person turning an approved tool to the wrong purpose remains inside the rules, and although ringfencing narrows the gap it does not close it.
  • Patching is somebody else's lever. Unapproved code is stopped. Whether the approved code happens to be three versions behind is not a question this lever asks. Patching sits over on the machines section.
  • A learning spell is genuine work. The list gets assembled from what you truly run, and that wants a fortnight of somebody paying attention. A firm unwilling to give it that fortnight should not buy this lever.
  • Servers and unmanaged kit are separate conversations. Counting and enrolment both happen by the endpoint. Anything outside that enrolment, a contractor's own machine included, goes uncovered by this lever.
LEVER 01

Heads up: card statements show FORTIFY 24X7 - ServiceShield IT is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.