What is our primary use case?
I primarily use it on servers. We deal with smaller customers, and they don't always have the money to get it on every endpoint. The main thing exposed to the internet is, of course, the server, RDP, and other functions.
We have some customers that have it on the endpoint. In the past few years of using ThreatLocker, I haven't experienced ransomware on servers. However, there are small occurrences on endpoints when they're not using ThreatLocker.
How has it helped my organization?
With ThreatLocker, we don't have shadow IT, and it has reduced ransomware.
We have a lot of companies concerned with compliance. They have an application list, and anything outside of that application list is not allowed. ThreatLocker makes that really easy for us since you just allow what they need, and no one can run anything else.
What is most valuable?
Ringfencing is a valuable feature. If someone gains access to something or some end user attempts to run malicious PowerShell commands to download malware, it simply doesn't allow it. It's like saying, I'm not permitted to reach out to this.
ThreatLocker eliminates shadow IT and reduces ransomware. We have many companies that need compliance. They have an application list, and anything outside of that list is not allowed. ThreatLocker makes this easy by allowing only what we need, preventing us from running anything else.
Previously, I used AppLocker, a Windows tool, which is a lot of work to manage. ThreatLocker reduced work, allowing us to hire fewer people for this job. The time saved from not having to do recovery when malware runs, which can't happen with ThreatLocker, also saves money.
It's fairly easy to use. It has a learning curve. However, if you go to the university, you should be fine. And if you don't know something, you can just click the chat button. You'll be chatting with someone in 30 seconds.
It reduces work. It helps us save on operational costs that way. You can hire fewer people or move people onto other stuff. People can be moved to other tasks. We likely save one FTE a year, so it saves us around 30,000 euros.
We can block access very well. They are doing their job.
It reduces the amount of time a ticket takes to action.
What needs improvement?
It doesn't really have to do with ThreatLocker as a company. It's really annoying when other companies don't sign their executables with a certificate, requiring new rules for new files. It would be beneficial if it became more recognized in the EU to gain respect. That's about the only issue I can think of.
For how long have I used the solution?
I have used the solution for a little bit more than three years now.
What do I think about the stability of the solution?
It's really stable. Once deployed, it downloads the policies locally, so even if the computer doesn't have internet, it doesn't matter. It still works.
What do I think about the scalability of the solution?
The scalability is great. I can put as many endpoints in it as I like.
How are customer service and support?
The customer service is very good. If I need someone, I hit the chat button, and 30 seconds later, there is someone there to help me.
Which solution did I use previously and why did I switch?
I used the Windows built-in AppLocker, and that was it.
How was the initial setup?
We use RMM to deploy the agent.
The initial setup had its ups and downs. That was all on us. We tried to roll it out for everyone at the same time. I'd advise against that.
What about the implementation team?
I had a Solutions Engineer help me. He was from ThreatLocker.
What was our ROI?
I would estimate savings equivalent to one person per year, which is about 30,000 euros in our country. Not dealing with recovery when malware runs, as it can't run, saves a lot of time and money. The subscription includes help desk time, saving us even more.
What's my experience with pricing, setup cost, and licensing?
The setup is quite cheap, considering what it does.
Which other solutions did I evaluate?
I didn't evaluate a different solution before choosing this one. Afterwards, I looked at Cyberfox for the elevation control, however, it was unsatisfactory.
What other advice do I have?
I rate the solution a ten out of ten.
If something isn't working, you get a helpdesk ticket. If they don't know the answer, they escalate and eventually hop on a call with you without automatically closing tickets. It's been great. My Solutions Engineer has been fantastic. Even as he's moved up within the company, I can still call him.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.