Right now, an employee can download software onto a company computer and run it without anyone checking first. That includes the fake PDF viewer, the cracked plugin and the installer that arrived as an email attachment.
Application allowlisting lets the business decide which software may run. Anything not approved is blocked until someone authorises it. It's one of the most effective controls against ransomware and it's a strong step towards Cyber Essentials.
The catch
Design practices run a long tail of software: CAD, BIM, rendering engines, plugins, viewers, survey tools. If staff can't get legitimate software approved quickly, allowlisting becomes an obstacle rather than a control. The approval route has to be fast and known.
How we approach it
Start in audit mode to learn what actually runs across the practice, build the allowlist from that, then enforce. Nobody's Revit stops working on day one.
Want to know what allowlisting would look like for your team? Ask us.
Want a hand with this? Talk to us.