A Fortify 24x7 brand. Security and continuity built around clinical work.Client sign inReach an engineer
Care Secure Systems
B
Wing B / Execution control

The safest workstation in a clinic is a profoundly boring one.

Detection asks whether something looks dangerous. Allowlisting asks a much simpler question: was this approved. A reception machine needs its clinical client, a browser, something to drive the scanner, and very little besides. Everything outside that short list can be refused by default rather than judged on the fly, and a refusal is far more reliable than a judgement.

ThreatLockerApproval listsRingfencingElevation
1 line / refuse unless approved / requests handled for you
Lines in this wing1
ProductThreatLocker
Counted asEndpoint
PostureDeny unless approved

Default deny survives things detection cannot

A detection engine is making a probability judgement about behavior. Most of the time it is right. Allowlisting is not making a judgement at all. If the software was not approved for this machine, it does not start, and it does not matter whether it is brand new, cleverly packed, or arrived inside a document.

That is a strong control and it comes with a real cost: somebody has to maintain the list of approved software. The line on this page includes that work. Elevation requests and approvals are handled by the team at Fortify 24x7, continuously, rather than landing in a practice manager inbox.

Ringfencing is the part people underestimate

Approving an application is not the same as trusting it with everything. Ringfencing sets out which other programs an approved application may launch, which files it may reach, and where it may send data. A spreadsheet application is allowed to be a spreadsheet application without also being a route to a scripting engine and out to the internet.

In a practice this matters most for the software that opens attachments all day: the office suite, the PDF reader, the browser. Those are approved, necessary, and the most common starting point for something unpleasant.

Approval requests peak in the first two weeks and then almost stop. That curve is the whole story of a rollout, and knowing it in advance is what keeps a practice from switching the control off on day four.
Lines in this wing

Line detail and rates

Each figure here is read live out of billing. Whatever you pick sits waiting on the side panel while you keep reading down the page.

Fortify-ZeroTrustLine detail

Application Allowlisting

ThreatLocker, with approvals handled around the clock

Software that was approved runs. Anything else is turned away, and the approval work is carried by our team rather than by whoever happens to be sitting at reception. A learning period assembles the opening list from what the practice genuinely uses, so nobody writes it from memory.

  • A learning phase watches what genuinely runs before a single refusal is issued.
  • Supplier updates are followed, so an approved program does not break on release day.
  • Ringfencing bounds what an approved program may start, open, and connect to.
  • Elevation and approval requests are handled continuously by Fortify 24x7.
ProductThreatLocker
PostureDeny by default, permit by approval
OnboardingLearning period first, enforcement second
UpdatesFollowed and approved automatically as suppliers ship them
ApprovalsHandled by Fortify 24x7, continuously
Counted asOne endpoint, charged monthly
Loadingper endpoint
charged monthly, in advance
QTY
Included scope

What you get on these lines

  • A learning period on your real machines before anything is denied.
  • Approval and elevation handling by our team, on every day of the year.
  • Ringfencing rules drafted alongside you instead of arriving as a preset.
  • Update tracking, so an approved application does not break on its release day.
Honest scope

Where this wing stops

Allowlisting is the strongest control in this catalog and the one most often abandoned during week one. Here is what it does not do.

  • An approved person misusing an approved program is a different problem. Somebody with a valid login opening records they have no business opening is not what this control is for. Wing E scores exposure, Wing A records the activity, and your own access review is what genuinely addresses it.
  • It changes how software gets installed, permanently. A clinician who used to download a utility and run it now raises a request. That is the control working. It is also a change of habit, and practices that skip the conversation up front are the ones that ask to turn it off.
  • It covers enrolled endpoints, not your vendor cloud. The hosted side of your electronic health record, your clearinghouse, and your payer portals run on infrastructure that will not take this agent.
  • It does not replace the monitoring in Wing A. An approval list refuses whatever was never approved. It says nothing about an approved tool being driven by hands that should not be on it.
  • A machine that was never enrolled is unaffected. Coverage follows enrollment here as it does everywhere else in the catalog.
NOTE 01

Heads up: card statements show FORTIFY 24X7 - Care Secure Systems is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.