We do IT differently.

Contact us for more information.

We do IT differently.

Contact us for more information.

ThreatLocker Managed Services

Zero trust allowlisting that fits how your people actually work. We set it up, tune it, and handle the approvals, so security gets tighter without your team getting stuck.

Does ThreatLocker make us HIPAA or CMMC compliant?

No single product does that on its own. ThreatLocker supports key controls that frameworks like HIPAA, CMMC, and NIST SP 800-171 expect, including restricting unauthorized software, enforcing least privilege, and keeping audit logs. We’ll help you fit it into your broader compliance program.

Can ThreatLocker run alongside our current EDR or MDR?

Yes. ThreatLocker works alongside other security tools, and we support other EDR, MDR, and XDR platforms as well, so we can fit it into the stack you already have.

Let’s talk about ThreatLocker for your business

Tell us a little about your environment, and we’ll walk you through what a ThreatLocker rollout would look like, how approvals would work day to day, and where it fits with the tools you already have. Or just give us a call.

Sierra Experts is veteran-owned, headquartered in Pittsburgh, and supports customers in 36 states.

Request a ThreatLocker consultation   Call 412.722.0707

Cybersecurity Services · Microsoft 365 Management · Zero-Trust Security

What ThreatLocker does

Application Allowlisting

Deny by default. Only the applications, scripts, and libraries you’ve approved are allowed to run. Everything else is blocked, including ransomware and unknown tools that antivirus hasn’t seen yet. ThreatLocker catalogs the software you already use, so nobody is building lists from scratch.

Ringfencing

Approved doesn’t mean unlimited. Ringfencing sets boundaries on what trusted applications can do: which files they can reach, which other programs they can launch, and whether they can connect to the internet. If an attacker hijacks Word or PowerShell, the application still runs, but the attack hits a wall.

Elevation Control

Your users can run specific approved applications with admin rights without being local administrators. Elevation can be limited by user, group, application, and time, and admins don’t have to type their credentials on everyday workstations.

Storage Control

Policies for USB drives and other storage: which devices can connect, who can use them, whether access is read-only or requires encryption, and which file types can be copied. File activity is logged, so you can see what was copied, moved, or deleted.

Why a certified partner matters

ThreatLocker is powerful, and it’s strict by design. Rolled out carelessly, it blocks the wrong things, piles up one-off exceptions, and frustrates people until someone wants to turn it off. Rolled out well, most users barely notice it’s there.

As a ThreatLocker certified partner and your IT provider, we already know your environment: the line-of-business apps, the vendor support tools, and the odd piece of software a machine on the plant floor depends on. When someone requests a new application, we see the request and understand the context, so approvals are quick and they make sense. We don’t just drop in allowlisting and walk away.

  • Policies built around the software you actually run, not a generic template
  • Approval requests handled by people who know your systems
  • One team for ThreatLocker, your endpoints, Microsoft 365, and the rest of your IT
  • A clean policy structure that doesn’t turn into a pile of exceptions over time

How we roll it out

1. Learning Mode

We deploy the ThreatLocker agent and let it watch. It records the applications, scripts, and dependencies your computers and servers use day to day. Nothing gets blocked yet.

2. Policy tuning

We review what Learning Mode found with you, clear out what shouldn’t be there, group applications sensibly, and add Ringfencing, Elevation Control, and Storage Control policies where they fit. We’d rather spend the time here than on help desk tickets later.

3. Secure Mode

Once the policies reflect a normal work cycle, including things like month-end or a production changeover, we switch machines to Secure Mode in stages. From then on, unapproved software doesn’t run.

4. Ongoing approvals and support

When someone needs new software, they submit a request from the ThreatLocker prompt. Our team reviews it and approves, adjusts, or declines it. We also keep policies current as vendors release updates and your business changes.

Compliance and cyber insurance

Application allowlisting and least privilege come up again and again in security frameworks and insurance questionnaires. ThreatLocker can help you show those controls are in place and working.

  • HIPAA: Limits which software can run on systems that handle patient data, and keeps a record of what ran and what was blocked.
  • CMMC and NIST SP 800-171: Supports requirements around restricting unauthorized software, enforcing least privilege, and controlling removable media.
  • Cyber insurance: Insurer questionnaires commonly ask about endpoint protection, admin rights, and how you stop unauthorized software. Allowlisting and Elevation Control give you clear answers, with logs to back them up.

To be clear, no single product makes you compliant or guarantees coverage. ThreatLocker is one strong control inside a broader security program, and we’ll help you fit it into yours.

Who it’s for

Manufacturing

Plant-floor PCs, HMIs, and engineering workstations often run older or specialized software that can’t be patched on a normal schedule. Allowlisting keeps those machines limited to what they need, and Ringfencing limits what that software can reach.

Healthcare

Practices and clinics handle patient data on shared workstations used by a lot of different people. ThreatLocker keeps those machines limited to approved clinical and business applications and gives you an audit trail of what ran.

Critical systems

Some systems simply have to stay up: file servers, ERP, production scheduling, lab systems. Deny-by-default protection makes it far harder for one bad click or one malicious download to take them down.

Frequently asked questions

How is ThreatLocker different from antivirus?

Antivirus looks for known bad software and tries to stop it. ThreatLocker starts from the other side: only approved software can run, and everything else is blocked by default. That means ransomware and unknown tools are stopped even if no one has seen them before. It works alongside your other security tools rather than replacing every layer.

Will ThreatLocker block software my team needs?

It can if it’s rushed, which is why we start in Learning Mode and tune the policies with you before anything is enforced. After that, if someone needs a new application, they request it right from the ThreatLocker prompt and our team reviews it.

How long does a ThreatLocker rollout take?

It depends on how many computers and servers you have and how much software they run. We keep Learning Mode on long enough to capture a normal work cycle, then move machines to Secure Mode in stages. We’ll give you a realistic timeline once we’ve seen your environment.

Who handles the application approval requests?

We do. Requests come to our team, and because we already support your environment, we have the context to make the right call and keep people moving.