A Fortify 24x7 brand. Managed security programs for multi-site organizations across North America.Rate scheduleClient sign in
Enterprise Secure Systems

Decide what runs, and the malware question gets smaller.

Detection asks whether something is malicious. Allowlisting asks a different one: was this ever meant to run on this machine. ThreatLocker answers the second question, which is the cheaper question to be right about, and it does so without needing to have seen the threat before. One line item, counted per endpoint.

Program
02 of 06
Platform
ThreatLocker
Line items
1 priced separately
Unit basis
Counted per endpoint under policy
Billing
Card, monthly in advance, no term
How it works

The mechanism, not the brochure.

Three things worth understanding about this program before you price it, written for somebody who will be asked to defend the decision internally.

01

Learning first, enforcement second

The agent spends its opening period cataloguing what your estate genuinely executes. The policy that results is built from your own software inventory rather than a vendor template, which is why enforcement does not begin by blocking the line-of-business application nobody remembered to mention.

02

Permitted is not the same as unlimited

Once something is approved, ringfencing still governs its reach: the files it may open, the other programs it is allowed to launch, and whether it gets to talk outbound at all. Where a document viewer has no legitimate reason to walk a network share, it is unable to, and that holds even after somebody has been talked into opening the attachment.

03

Elevation without local administrator

People who need to install software can request elevation for a specific action instead of holding administrative rights permanently. Requests arrive at a staffed desk during business hours rather than sitting in a queue that nobody has been made responsible for.

Line items

The line item in this program.

Each control is priced against its own unit and can be bought without the others. Rates come live from the billing catalog. Anything added here is held in the schedule and checked out from the rate schedule.

Fortify-ZeroTrust

Application Allowlisting

ThreatLocker policy running on the endpoint: allowlisting, ringfencing to bound whatever an approved program is then able to reach, storage control across removable drives and network shares, and elevation for staff who must install things without carrying local administrator rights around permanently. The learning period builds the policy from your own inventory.

Loadingper endpoint
published rate, per month
Units
Where this program stops

What these line items do not do.

Allowlisting is both a powerful measure and a deliberately narrow one. It is worth being precise about the edges.

Of everything in this catalogue, this is the control most often responsible for the incident that never happened and therefore never got written up.

The other programs

What sits alongside this one.

Any program can be bought on its own. Most estates end up running several, and the reason they work well together is that one desk operates all of them.

Notice

Heads up: card statements show FORTIFY 24X7 - Enterprise Secure Systems is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.