Application allowlisting protects developer machines by only letting approved software run and blocking everything else by default. Using a tool like ThreatLocker, that means ransomware, malware and unknown programs simply cannot execute, even on busy engineering machines that install plenty of legitimate tools. For a software firm holding valuable code, it is one of the strongest protections you can have.
Most security tries to spot what is bad. Allowlisting flips that around: it only permits what you have approved. Here’s why that suits a development environment.
1. It blocks ransomware before it runs
Ransomware has to run a program to do its damage. If only approved software is allowed, it never gets to start, which is a far stronger position than relying on detection alone to catch brand-new threats.
2. It suits machines that install lots of tools
Developers download and run many tools, which is exactly where unknown or risky software can creep in. Allowlisting lets you approve the genuine tools while keeping everything unvetted off the machine.
3. It limits the damage of a mistake
Even careful people occasionally run the wrong thing. With allowlisting in place, a mistake is far less likely to turn into an incident, because the malicious program cannot execute.
4. It keeps machines clean and consistent
Allowlisting also stops unapproved software building up on work machines, which keeps your fleet secure, consistent and easier to support. You decide what runs on your firm’s computers.
A real example: approved tools, nothing else
We supported a software company serving financial trading firms using application allowlisting across its developer machines. We processed controlled requests to permit legitimate engineering tools, such as an SSH client and hardware drivers, while every new executable was vetted before it could run, protecting source code and IP.
For most technology and trading firms, this sits within fully managed IT at about £45 to £100 per user per month, billed per user, with the security and resilience these businesses rely on built in.
Why technology and trading firms choose First Stop IT
First Stop IT has supported businesses since 2002, including software and technology companies and firms that serve financial markets. We know the systems these teams depend on: secure VPN and remote access, source control and build pipelines, virtual dev and test environments, Microsoft 365 and Teams, and the security that banks and regulators expect, from multi-factor authentication and endpoint protection to application allowlisting and email security. We work with technology and trading firms in London and across Essex and Hertfordshire. Our credentials include:
- Cyber Essentials Certified
- IASME Cyber Assurance (Gold)
- NCSC Assured Service Provider (Cyber Advisor for Cyber Essentials)
- Microsoft Partner
- Crown Commercial Service Supplier (G-Cloud)
- Quality Principles Certified
We look after more than 2,000 endpoints across 50 companies, we’ve been named a Top 50 UK MSP for three years running, and we support organisations with 10 to 100 employees across Essex, Hertfordshire and London, including Harlow and Bishop’s Stortford.
Book a free IT and cyber security review
Want ransomware blocked before it can run? Book a free IT and cyber security review with First Stop IT and we’ll show you how allowlisting protects your firm.