Whether you’re a one-person operation or a growing business with a full team, we’re here to help. Get in touch and let’s talk about what we can do for you.

ThreatLocker Ringfencing

Contain what approved applications can do — stop attacks that exploit trusted software

Just because software is trusted doesn't mean it should be able to do anything. Ringfencing controls exactly what each approved application is allowed to interact with — so even if an attacker exploits a legitimate tool like Word or a browser, the damage they can do is contained.

Key Features Of This Package

Application containment

Defines strict rules for what each approved application can access — files, other processes, network connections. Legitimate software keeps working. Malicious actions are stopped.

Stops 'living off the land' attacks

Prevents common attack techniques that hijack trusted tools — like using Word to launch PowerShell or a browser to download malware.

Works alongside Allowlisting

Ringfencing layers on top of Allowlisting — the combination means software has to be both approved AND behave correctly.

Approved doesn't mean unrestricted.

Adam Gillett, Head Of Business Partnerships - We Do Your IT Support

What Is Our ThreatLocker Ringfencing

ThreatLocker Ringfencing controls what approved applications are allowed to do on a device — which files they can access, which other applications they can launch, and what network connections they can make. It prevents attackers from weaponising trusted software.

Why Choose Our ThreatLocker Ringfencing

When you want to stop sophisticated attacks that exploit legitimate applications. Included in the Complete Device Security Pack alongside Allowlisting, Storage Control, and Network Control.

What's Included In Our ThreatLocker Ringfencing

Per-application behavioural rules, process interaction controls, network access restrictions per application, and logging of all rule events.

Benefits Of Our ThreatLocker Ringfencing

Stops 'living off the land' attack techniques, contains the damage if an application is compromised or exploited, and adds a critical layer of defence that antivirus and even Allowlisting alone cannot provide.

How to become a customer

Step 1

Initial Enqiry

Step 2

Advice

Step 3

Setup

Step 4

Call For Support

Step 5

Billed In Arrears
Frequently Asked Questions About ThreatLocker Ringfencing
We have complied a list of questions that are often asked about ThreatLocker Ringfencing and how it can help your business. If you can’t see the answer to a question you have, please contact us today!

Yes. A common attack technique is embedding a malicious macro in a Word document that launches PowerShell to download malware. Ringfencing can be set to stop Word from launching PowerShell entirely — so even if the macro runs, it hits a wall.

Rules are built carefully based on how applications legitimately behave. Ringfencing policies are tested before going live so legitimate functions continue to work as expected.

Allowlisting controls what runs. Ringfencing controls what approved software is allowed to do. They’re complementary — Allowlisting is the first gate, Ringfencing is the second.

Yes. You can define what a browser is and isn’t allowed to do — for example, preventing it from writing executable files to disk, which is a common malware delivery method.

It’s an attack technique where hackers use tools already on your system — PowerShell, Command Prompt, scripting engines — rather than installing their own malware. Because the tools are legitimate, antivirus often misses it. Ringfencing stops the abuse of these tools.

Yes. Each application gets its own set of rules appropriate to what it legitimately needs to do. Word has different rules from a browser, which has different rules from a database client.

No. The rules are evaluated at the OS level and have negligible performance impact on end users.

No — it works at the application layer on the device. ThreatLocker Network Control handles host-level firewall rules. Ringfencing focuses on what applications are permitted to do, not network traffic.

The action is blocked and logged. Your IT team can review the event and, if it’s a legitimate function we haven’t accounted for, update the rule accordingly.

Yes. ThreatLocker provides managed policies for common applications, so you don’t need to build rules from scratch. We configure and maintain them for you as part of your managed service.

Reassuring Availability

There is nothing more annoying than an IT glitch that stops you working efficiently. However, knowing you have access to immediate attention to the glitch and a solution to it, is very reassuring and that is provided by We Do Your IT. We have so appreciated the availability and response given by the team at We Do Your IT, enabling us to remain a productive firm.

Richard Sharp – Sharp Family Law