A Fortify 24x7 brand. Security controls built for firms the Safeguards Rule applies to.Account sign inAsk an engineer
Equity IT Solutions
Register 02 / Application control

Nothing executes on that workstation unless your firm put it on the list.

Most protection is an argument about whether a file looks dangerous. Application control declines the argument entirely. A workstation runs what your firm approved and turns away everything else, regardless of whether anybody recognises it, regardless of how new it is, and regardless of who was talked into opening it.

ThreatLockerRefused by defaultRingfencing
1 entry / refused by default / observation period included
Entries here1
UnderneathThreatLocker
Billed againstEach workstation
Aimed atMachines holding client files

Turning something away beats recognising it

Detection must be correct about something it has never encountered. Refusal only has to be correct about something your firm already wrote down. That imbalance is why application control is the strongest single safeguard available to a small practice, and equally why it is spoken about as awkward.

Awkward is what happens when it gets switched on carelessly. An observation period studies how your office genuinely operates first, so the tax package, the custodian utility, the reporting tool somebody wrote in 2011, and the printer driver are all recorded before anything starts being turned away.

Detection must be correct about something it has never encountered. Refusal only has to be correct about something your firm already wrote down.

Ringfencing, and why it earns its keep

Approving a program is only the first decision. The second is what an approved program may do once it is running. A spreadsheet has no reason to launch a scripting engine, and a document reader has no reason to open a connection to an address it has never visited before.

Ringfencing draws those boundaries, which is how a legitimate program stops being usable as the vehicle. A great deal of what arrives by mail in this industry works by borrowing software you already trust rather than installing anything at all.

What your office will actually notice

For a fortnight you will be approving things. After that most practices report a handful of requests each month, usually a fresh version of something familiar, and approving one takes about a minute from a phone.

Setting that expectation plainly beats selling this as invisible, because invisible is not what it is. Occasionally a member of staff will notice it, and the moment they notice is precisely the moment it is doing its job.

Entries on this register

Specification and rate for each one

Rates below are read live from the billing service. Anything you record sits on your order sheet while you carry on reading the rest of the register.

Fortify-ZeroTrustRate and detail

Execution Control

Refused by default on the workstation. Listed software executes, everything outside the list is turned away, and what the listed software may touch afterwards is drawn tight around what it genuinely needs.

Allowlisting with ringfencing and elevation, from ThreatLocker
  • An observation period assembles the opening list out of software already in daily use.
  • Vendor releases are tracked, so an ordinary update does not shut a preparer out in April.
  • Ringfencing pins down which processes, files, and addresses a listed program may reach.
  • Elevation lets one task run with rights the member of staff does not keep afterwards.
  • Requests land with our engineers and get answered by a person rather than a queue.
Supplied byThreatLocker
Machines it reachesWindows and macOS workstations
Standing postureTurn away by default, against a list your firm owns
Before enforcementAn observation period, so the list starts complete
Who answers requestsFortify 24x7 engineers, individually
Charged againstEach workstation, every month
Readingper endpoint
collected monthly, ahead of the period
UNITS
Honest scope

Exactly what this register does and does not reach

Two columns, both of them written to be relied on. The right hand column is the one worth reading twice, because a firm that misreads it will believe an obligation is covered when it is still open.

What is included

  • Licensing and agent rollout across every workstation you enrol.
  • An observation period, followed by construction of your approved software list.
  • Continuing upkeep of that list as vendors publish new releases.
  • Ringfencing rules for whichever programs handle client files.
  • Elevation, so routine tasks stop requiring a permanent administrator account.
  • Requests answered by our engineers instead of an automated approval queue.

What is not included

  • Servers and cloud workloads. This entry is written for workstations only.
  • Assurance that nothing will ever be turned away inconveniently. Sometimes it will.
  • Authority over software running on a personal machine that never enrols.
  • Setting your policy on what staff may install. That decision belongs to your firm.
  • Filtering of web content, which is sold over on the device oversight register.
  • Watching or reacting. Turning execution away and investigating an event are separate jobs done by separate products, and we charge for them separately.
BILLING ENTITY

Heads up: card statements show FORTIFY 24X7 - Equity IT Solutions is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.

Equity IT Solutions raises no separate charge of its own, so a second line will never turn up beside that one.