A Fortify 24x7 brand. The dispensary counter for healthcare technology.Sign inAsk us something
MediSafe Networks
Drawer II / Locked press

The press stays locked, and only approved preparations come out of it.

Every dispensary keeps a press that opens for one reason and refuses every other. Endpoints can run on the same principle. Approved software executes; unrecognised software gets no hearing at all. Fitted to a reception machine opening the same few clinical applications daily, nothing else on this site pays back as well.

ThreatLockerDeny by defaultApprovals worked by our desk
1 preparation / deny by default / approvals in minutes
Labels filed here1
Compounded onThreatLocker
Measured byEndpoint
Approval deskWorked by our desk

How deny by default feels in a working practice

The opening stretch is a learning phase. Rather than begin from a list drawn up by somebody at a vendor who has never stood in a dental practice, the agent watches what your staff genuinely run and assembles the permitted set out of that. Nothing gets blocked during it. After it, an unfamiliar file needs a decision made about it.

A Fortify 24x7 engineer takes those decisions, and in practice they come back within minutes. None of that removes a step which was not there a week ago, and we would rather write it down than let a busy clinic explain it. Somewhere that installs new tooling constantly will feel it. Somewhere running the same few clinical applications day after day will barely notice, and those machines are exactly where the money comes back.

No hearing is ever granted to the unfamiliar binary. That is the idea, entire.

Where to put it first

Begin wherever a loss would hurt most: whichever machine reaches the practice management database, whichever one moves money to and from the payers, and the reception computer that spends its day opening whatever the post brings. A tight policy usually goes on those three, and something easier everywhere else.

The ringfencing half gets talked about by nobody. Once a tool is permitted, the fence goes round it: which processes may be started, which files opened, which addresses reached. That fence is the reason a wholly legitimate utility does not become a handy way of walking records out of the building.

Labels in this drawer

What is filed here, and what each one costs

Billing supplies these figures directly. Add something and it stays on your script, untouched, for the rest of the page.

Fortify-ZeroTrustFormula

Execution Control

ThreatLocker, deciding what is allowed to run

Detection wagers that the bad thing gets recognised quickly enough. Allowlisting places a different wager: execution belongs only to software somebody approved, so a file nobody knows never gets to plead its case. Put it on a machine running the same six clinical applications every day and no control on this site does more.

  • A learning stretch assembles the permitted set, drawing it from the software your people actually open.
  • Updates from a vendor are tracked, so nobody at reception is locked out by a routine release.
  • A ringfence bounds the processes, the files and the destinations an approved tool may go near.
  • An elevation request reaches whichever Fortify 24x7 engineer is on shift, day or night.
Made up forMachines with a settled application list: reception, billing, imaging review
Acts onExecution itself. Approved software runs and nothing else does
Shelf lifeThe permitted set is kept current the whole time this runs
Dispensed byThreatLocker, with an approval desk kept staffed by Fortify 24x7
Counter-checkedThe asker and the approver are both entered in the log
Weighingper endpoint
counted per machine, charged monthly
QTY
Read the label

Where this drawer stops

What may execute is settled here. What a human being decides to approve is not, and the gap between those two is worth grasping before a card comes out.

  • It governs code, not consent. No allowlist is consulted by anybody opening an approved browser, arriving at a convincing page, and typing a password. Covering that road is a job for the front counter drawer and the filtering line.
  • Sealed clinical equipment sits outside it. Plenty of modalities, analysers and dental sensors carry a vendor ban on third party software, and this agent stays off every one of them. That problem belongs to segmentation and to vendor management. Calling an allowlist its answer would be a lie.
  • The learning phase takes a real week. Hours have to come from somewhere for this. Run as a checkbox exercise, it buys a bad opening month and a team weary of it all by autumn.
  • Reading and classifying files is elsewhere. Ask amber glass which documents carry identifiers and how far those have drifted. Execution is the single question this drawer settles.
  • It does not make anyone HIPAA compliant. Technical safeguards get propped up here. The program above them stays with you, as does the risk analysis, as do the policies, as does the training file.
NOTE 01

Heads up: card statements show FORTIFY 24X7 - MediSafe Networks is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.