A Fortify 24x7 brand. Security operated for the plant, the depot, and the offices behind both.Sign inRaise a job
Industry LockNetworks
Board 01 / Managed security for industrial operators

Isolate it, tag it, then let people work.

A running plant is made safe to touch by putting a lock on every energy source and a tag on every lock. Company information deserves the same discipline. We fit the controls, we label what each one holds, and we staff the desk that decides when something gets released. Your maintenance planner should never be the person triaging an alert at four in the morning.

24 lines / 10 platforms / a single monthly figure
ONE ISOLATION POINTSUPPLY OPEN1ENDPOINTS2MAILBOXES3IDENTITIES4HELD COPIESFOUR LOCKS, ONE RELEASEFIG.1SUBJECTGROUP HASPLOCKS FITTED4 OF 4ISSUEA
OperatorFortify 24x7
On the board24 lines across six bays
Counted byIts own unit, monthly
SettlementCard only, taken up front
Fig. 02 / Hazard register

The loss that stops a plant begins in the office.

What actually stops an industrial business is quieter than that, and it almost always starts in the office rather than on the floor. These four turn up on nearly every site we are asked to look at, and none of them needs a sophisticated attacker.

Hazard 01

The line stops and the office cannot help

Ransomware rarely reaches the machines that turn the shafts. It reaches the machines that hold the schedule, the drawings, the customer orders, and the dispatch notes. Production capacity is intact and completely useless, because nobody can say what to make.

Hazard 02

The mailbox that authorizes payment

Purchase orders, supplier bank details, and a signature on a variation all move through one inbox. Take that inbox and there is nothing further to break: you simply ask, in a voice the accounts team already trusts, and the money leaves on the next run.

Hazard 03

Contractors, agency staff, and the shift that never handed back

Industrial sites run on people who arrive for a project and leave. Their accounts outlive them, their laptops were never yours, and the badge came back while the login did not. Every site we look at has a handful of these still live.

Hazard 04

The one server standing in the corner of the plant office

It runs a license dongle, a twenty year old application, and the only copy of the maintenance history. It has never been patched because nobody dares, and the backup, if there is one, has never once been restored.

Fig. 03 / The bays

Six bays. One subscription. One desk that picks up.

Fit the bays you want and leave the others standing. Each line carries its own per-unit monthly rate, and the whole set lands on one invoice. Each bay sheet says what the line covers, what it costs each month, and the point at which its authority stops.

BAY 01

Detection and response

Plant · SentinelOne + Fluency

Software on the machines, a single joined record covering the estate, and analysts whose job is to act, not to send a chart round on Monday.

  • Behavior-based detection for Windows machines, Mac machines, Linux machines, and Kubernetes nodes.
  • Fluency stitches the sources together so a finding arrives carrying its context.
  • Three levels of response, running from notify only up to containment and reversal.
Read the bay sheet
BAY 02

Execution control

Plant · ThreatLocker

Nothing runs on a machine holding work you cannot lose unless it was approved first. Software nobody signed off does not get a turn, whatever it calls itself.

  • Learning mode watches first and writes the allowlist from what your shifts actually open.
  • Vendor updates get tracked, so a patch does not shut a line down on a Tuesday.
  • Ringfencing fixes which files a permitted application opens, which processes it starts, and where it may reach.
Read the bay sheet
BAY 03

Mailbox defense

Plant · Ironscales

Protection that lives within the tenant, whether the tenant is Microsoft or Google, alongside training that leaves your staff harder to talk around.

  • Connects over API, and therefore inspects a message already delivered into the mailbox.
  • Impersonation detection and account takeover detection, both tuned to your own tenant.
  • Simulations and short coursework aimed at whoever the results say needs it.
Read the bay sheet
BAY 04

Device fleet

Plant · N-able N-sight, with Addigy for Apple and Zimperium for handsets

Machines kept patched, browsing kept filtered, Macs kept managed, and the handsets your supervisors approve things on finally watched by somebody.

  • N-able N-sight handles the monitoring, the patching, the scripting, and the remote hands.
  • Web and name filtering comes off that same agent, and nothing needs racking.
  • Addigy handles Apple hardware; the iOS and Android handsets go to Zimperium.
Read the bay sheet
BAY 05

Data protection

Plant · Actifile

Locate the sensitive material first. A folder nobody ever located cannot be governed. Rules come after that.

  • Sweeps endpoint storage and file shares, hunting regulated or commercially sensitive material.
  • Puts a score on each device, which is what gives the remediation queue a sensible order.
  • Encryption, plus control over the exits that data genuinely uses.
Read the bay sheet
BAY 06

Backup and continuity

Plant · N-able Cove, alongside Dropsuite

Copies held clear of whatever they cover, plus restores that get run on a rota instead of taken on trust.

  • Whole-disk and file-level copies, off workstations, off bare metal servers, and off guests.
  • The Microsoft tenant is N-able Cove work. Dropsuite takes the Workspace tenant, the ledger, and the Entra ID directory.
  • Restore verification on a rota, so recovery becomes evidence instead of a belief.
Read the bay sheet
Fig. 04 / Plant list

Nothing here was invented on the premises. We run it.

It has become normal for a seller to imply that the managed service was built on their own premises. This one was not. Underneath Industry Lock Networks sit commercial platforms chosen for how they behave when a site is under real load. Fortify 24x7 licenses them, and engineers who spend a whole shift inside them run them. A named platform and a phone number that a person answers beats a sealed box.

SentinelOne

Detection on the endpoint and autonomous response, over every operating system on this board, Kubernetes nodes included.

Fluency

Sources correlated and retained, so a finding shows up with its story attached.

ThreatLocker

Allowlisting for applications, ringfencing, and elevation control, on whichever machines matter most.

Ironscales

Mail security at the mailbox, wired in by API within the tenant. It protects at the mailbox and is not a gateway, so we will not describe it that way.

N-able N-sight

One agent does the monitoring, the patching, the scripting, the remote hands, and the name filtering.

Addigy

Running the Mac and iPad estate, once that estate has finished being unmanaged.

Zimperium

Threat defense that runs on the handset itself, across whatever iOS and Android hardware your supervisors use.

Actifile

Locates the sensitive material, scores how exposed each machine is, and encrypts whatever travels.

N-able Cove

Whole disk copies and file copies, taken off a workstation, off bare metal, off a guest, and out of the Microsoft tenant.

Dropsuite

The Workspace tenant copied, the Entra ID directory settings copied, and the QuickBooks Online ledger copied.

Every platform named, every one of them licensed through Fortify 24x7
Fig. 05 / The walk-down

What a first fortnight really involves.

Nothing here calls for a steering committee. Two weeks tends to cover it, and what takes the time is tuning and not deployment.

Walk the site

Half of one hour on a call. Machine counts, the platforms under them, who holds the administrator accounts, and which loss would genuinely stop dispatch. You walk away with a list of the lines and one figure per month, not a slide deck.

Card on the board

You settle the worklist here. Stripe collects the card details and none of them come to us. Charging is monthly and it happens before the month, under FORTIFY 24X7 on the statement.

Fit the locks

Installers and enrollment links turn up in the portal, normally inside the working day. Windows, Mac, Linux, and handsets each go their own way, and not one of those ways puts you inside a vendor console.

Settle the tuning

The allowlist finishes learning, exceptions accumulate against the filter, and backup windows end up cut to the volumes you genuinely hold. That is the week deciding whether a rollout finishes quiet or noisy.

Under watch

Findings go to our engineers rather than into your inbox. The portal remains yours: the lines, the installers, and the history of every job raised, and somebody real answers when you use it.

Fig. 06 / Where our scope ends

What this board will not do for you.

Marketing in this industry likes to promise cover with no gaps anywhere in it. This page will not, because a subscription with no gaps has never been on sale. What follows is the outer edge of what ours honestly reaches, published ahead of the purchase rather than produced afterwards.

  • This does not reach the plant floor control network. Every line on this board protects information technology: endpoints, mailboxes, identities, and data. None of it secures PLCs, SCADA, historians, safety instrumented systems, or the production control network. Anyone selling you an office security subscription as OT coverage is describing something they have not built.
  • This is not insurance. No line here pays money out when things go wrong. That is what an insurance policy is for, and you should hold one. Underwriters increasingly want controls of exactly this kind fitted before they will quote at all.
  • Authority to read is authority to remove. Anyone cleared to read a file is also someone capable of walking out holding it. Offboarding discipline, a regular review of who can reach what, and what your employment contracts actually say. Those are the controls, and software is not among them.
  • Nothing here tests the product you make. Firmware in a shipped unit, code inside an embedded controller, and the application your engineering team writes are separate disciplines. That is separate work, and we will name it rather than quietly imply this covers it.
  • Coverage follows enrollment. Enrolled hardware and connected tenants are what a line reaches. Everything else is outside it. Anything nobody enrolled stays invisible to all of it, and we would rather write that down now than explain it to you during an incident.
Fig. 07 / The board

Twenty four separate lines, each with its own counting unit.

Prices arrive from the billing service while the page opens, so the tag and the card cannot disagree. Put the lines you want on the worklist, fix the counts in the panel that slides out, and settle it when the totals look right. The whole worklist becomes a single monthly subscription.

The board came up empty. A reload usually clears that. If the rates stay blank, write to support@industrylocknetworks.com and a quote gets priced out by hand.
01Bay

Detection and response

SentinelOne + Fluency

Endpoint and node, with three levels of response behind them. Open the bay sheet.

Reading the board
02Bay

Execution control

ThreatLocker

Nothing runs on a machine unless it went on the list first. Open the bay sheet.

Reading the board
03Bay

Mailbox defense

Ironscales

Protection inside the mailbox, and the training that sits beside it. Open the bay sheet.

Reading the board
04Bay

Device fleet

N-able N-sight, with Addigy for Apple and Zimperium for handsets

Windows, Apple, and the handsets, all held in a known state. Open the bay sheet.

Reading the board
05Bay

Data protection

Actifile

Find the sensitive material, then set the rules for where it travels. Open the bay sheet.

Reading the board
06Bay

Backup and continuity

N-able Cove, alongside Dropsuite

Servers, workstations, and the cloud accounts that go uncopied. Open the bay sheet.

Reading the board
Money side

Heads up: card statements show FORTIFY 24X7 - Industry Lock Networks is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.

Worklist0 on the worklist$0.00/mo