A Fortify 24x7 brand. Security operated for the plant, the depot, and the offices behind both.Sign inRaise a job
Industry LockNetworks
Bay 02 / Execution control

Nothing runs unless somebody put it on the list.

Execution control is the software version of a padlock on a disconnect. The machine is held in a known state, the approved list is what defines that state, and anything arriving from outside it has to be signed on before it can move. It removes an entire category of argument about what a detection product may or may not have caught in time.

ThreatLockerAllowlistingRingfencingElevation control
Every tag in this bay carries its own counting unit
Tags in this bay1
Plant on the lineThreatLocker
One unit equalsThe endpoint
ApprovalsWorked at any hour

The learning phase does the hard part

Nobody hand-writes an allowlist for a working business, and any vendor suggesting you should has never tried. The agent runs in learning mode first and records what your shifts genuinely open: the ERP client, the CAD viewer, the label printer utility, the ancient thing the calibration rig will not run without.

That inventory becomes the list. Everything on it keeps working. Everything else has to be requested, and a Fortify 24x7 engineer picks the request up rather than leaving it queued until Monday.

Ringfencing, and why updates do not lock you out

Sitting on the list does not mean being trusted with everything. Ringfencing decides which files a permitted application may open, which processes it is allowed to start, and how far out it may reach. That is the difference between a document tool that opens documents and a document tool that also runs scripts.

Vendor updates get tracked continuously, so a routine release never turns into a production stoppage at the start of a shift. That single behavior is what makes default deny survivable in a business that cannot pause.

A padlock does not ask whether the person reaching for the handle meant well.
Tags in this bay

Specifications and rates

Every rate on this page comes live off the billing service. Lock it on and it stays on the worklist while you read on.

Hasp open, tags below
Fortify-ZeroTrustDanger tag

Execution Control

Plant · ThreatLocker, allowlisting and ringfencing at the endpoint

Default deny on machines holding work you cannot lose. Software nobody signed off gets no say at all in whether it runs, which retires an entire class of argument about what a detection product might or might not have caught.

  • Learning mode records what gets opened, and that recording becomes the list.
  • Vendor updates get tracked, so no shift is lost to a release landing on a Tuesday.
  • Ringfencing settles the files a permitted application may open, the processes it may start, and the places it may reach.
Mounted onThreatLocker agent on each endpoint you enroll
IsolatesAny executable that is not on the approved list for that machine
Retained forThe approval record, retained the whole time a line is running
Released byA Fortify 24x7 engineer approving the request, at any hour
Signed off byThe requester and the approver, both named on the approval
Readingper endpoint
settled one month ahead
QTY
Honest scope

Where this bay stops

A single line, a single job, and a hard edge around it. What follows is what execution control does not do, written down ahead of a purchase and not after.

  • It does not run on plant equipment. The agent installs on Windows and supported server platforms. It does not go on a PLC, a robot controller, or an operator panel, and nothing in this bay hardens a production control network.
  • An approved application can still be misused. What may run is decided here. What somebody does with it afterwards is not. Somebody with legitimate access to the ERP can still key in something ruinous.
  • It needs a named approver on your side. Requests get worked quickly, but exceptions that change your risk are yours to accept. One person who can decide without convening a meeting keeps the whole thing moving.
  • Learning takes real time. A short learning phase on a busy fleet produces a short list and a stream of interruptions. We would rather run it properly for a couple of weeks than switch to deny on day two and spend a month apologizing.
  • Execution control is no substitute for detection. Execution control and detection answer different questions. Plenty of customers run both. Saying that out loud beats selling one as though it covered the other.
Money side

Heads up: card statements show FORTIFY 24X7 - Industry Lock Networks is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.