Skip to content

Application control

Application control, rolled out without stopping the business.

Application control blocks more attacks than almost any other Essential Eight strategy, and it is the one most organisations leave until last. We build the rules from what your people run, prove them in audit mode, then enforce in rings.

  • Fixed fee, paid by milestone
  • Microsoft Partner
  • AZ-104 and AZ-305 certified engineers
  • Senior engineers only
  • Brisbane-based, working across Australia
See the full Essential Eight service

Why it is hard

Every organisation has software nobody remembers installing, scripts that run at 2 am and a finance tool from 2012. Switch on enforcement blind and something important stops. That fear is why application control is so often the strategy holding an organisation at Maturity Level Zero.

A checklist of six security findings, four ticked as closed and two still open, connected to three areas of work: identity, endpoint and detection.

How we deliver it

  1. Inventory: what runs today, from Defender and audit logs across your devices.
  2. Policy: App Control for Business rules that allow what your people need and block the rest.
  3. Audit mode: the policy logs what it would block until the logs are clean.
  4. Enforcement in rings: IT first, then pilot groups, then everyone.
  5. Exceptions: a fast route for new software, with an agreed turnaround and an owner for each approval.
  6. Handover: the rule process documented, so new applications are added without reopening the project.

What you receive

  • Your application control rules, recorded and handed over
  • A register of approved software and who owns each entry
  • An exception process your service desk can run
  • Evidence against the application control requirements for your target level

How long it takes

Two to four weeks for small organisations, and six to ten weeks for mid-sized estates with many line-of-business applications. It is a fixed fee, paid by milestone.

Questions buyers ask

What about servers?

Internet-facing servers are in scope from Maturity Level Two, and all servers at Level Three. We scope them separately, because server applications and change windows differ from workstations.

What happens when someone needs new software?

They request it through the exception route. The owner approves it, the rule is added and the change is live within the agreed turnaround.

We tried application control before and it failed. What is different?

Usually the earlier attempt went straight to enforcement, or built rules by hand. We build rules from real usage, prove them in audit mode and enforce in rings, so problems show up in logs before they reach users.

Start a conversation

Switch on application control without the outage.

Tell us about your estate and your target level.

Talk to an Engineer