What is our primary use case?
When we assessed application whitelisting and ringfencing controls, we decided to sign on with ThreatLocker. The way we operate our business is that it is deployed across all our clients. Once we identified the benefits of application whitelisting, we knew it belonged in every client's setup, and we implemented it for all our clients.
How has it helped my organization?
When we adopted ThreatLocker Zero Trust Endpoint Protection Platform, there were frustrations among clients as everybody was learning and getting used to it. We were learning how to administer it, and our customers were learning what it was, but it ended up becoming a fantastic thing where we now get referrals from our customers to other companies. Over time, it transformed into a positive experience, leading to customer referrals and advocacy for ThreatLocker. Although some clients overstate it by claiming it makes them ransomware-proof, the product's impact is undeniable. The contributions of Ben and Garrett were pivotal in this success, resulting in enthusiastic customer recommendations.
It has not helped eliminate or consolidate any security tools or solutions. We do not see ThreatLocker as a replacement for any of the current base functionality of existing tools; we see it as augmenting it. We see it as something that is important to have. One of the philosophies at our company is that we do not believe there should ever be an all-in for any security product. There should always be a check and a balance in place. One of our main checks on ThreatLocker is Huntress, so we use them in combination. It is something that maintains a balance. They are not overlapping by any means. Even though ThreatLocker has an MDR product now, we are electing not to use it because we want to have a separation and those checks and balances in place.
We initially anticipated a reduction in ticket hours through elevation control, but rather than a decrease, over the years, the nature of the tickets changed. Instead of broad, permissive policies, we now focus on diligent policy creation, accompanied by an increase in technical costs. I do not see that as a negative. While it increased our overall technical costs on an average basis, the benefits that come with it make it completely worthwhile and something that I would recommend to every MSP.
It has not decreased help desk tickets. It has changed the nature of the tickets, and that is not a bad thing. It means that we are using ThreatLocker properly, and we are not making broad sweeping policies that are overly permissive. It requires us to do our job a little more diligently.
It has increased our operational costs, but it is entirely worth it to increase those operational costs.
It can block access to unauthorized applications. It is very dependent upon the implementation and the access that is allowed. If you are giving this to your technicians without the appropriate training, it can be dangerous and not helpful. It can be a false sense of security, but if you implement it properly and are willing to make the investment in training your team properly on how to manage ThreatLocker, it is fantastic.
It has changed what our IT team is working on. Instead of working on old-style things, such as GPO or CryptoLocker policies and reviewing enforcement and deployment of that GPO and linkage, they are now spending their time reviewing policies within ThreatLocker. There is a shift in focus, but it is far more worthwhile. Every hour that has been replaced with ThreatLocker time is a much more effective use of their time.
What is most valuable?
Application whitelisting is significant, though it may seem obvious. What sets ThreatLocker apart from competitors offering similar solutions is ringfencing. The ringfencing controls, along with the application elevation features, keep it out of the user's line of sight while still protecting them. This protection is unobtrusive but effective, as users are protected without their awareness.
What needs improvement?
I find that the learning mode is too accessible. Technicians sometimes default to it instead of manually building policy controls. I would prefer the learning mode to be harder to access, ideally hidden behind a layer that requires creating at least one policy first before using the learning mode as a supplement.
Because of the accessibility of things like the learning mode, it moves towards defeating the purpose. The level of learning and the processes required to use ThreatLocker properly is high. You require a very high-tech person to truly understand its in-depth nature. We have tried it with our junior techs, and they just default to throwing learning mode on everything. It is too easy and allows techs to push through things that they should not. When you are using it properly, it has a high learning curve and a high difficulty level.
It requires quality-of-life enhancements from an administrative perspective. Currently, there is a strong technical focus but less emphasis on the business aspects, such as billing and portal administration.
For how long have I used the solution?
I believe we have been with ThreatLocker for about three years.
What do I think about the stability of the solution?
The platform's stability is solid, but I have concerns over their rapid expansion into areas like the endpoint solution acting as an EDR. They might be trying to become an all-in-one solution instead of focusing on their niche of augmenting other solid solutions. Companies like SentinelOne and Huntress have strong offerings, and ThreatLocker excels in complementing them instead of competing directly.
What do I think about the scalability of the solution?
It is quite scalable. This scalability is partly due to our implementation strategy, where every client receives it without exception.
How are customer service and support?
It has been fantastic. The feedback from our technicians working with Cyber Heroes has been positive, and my experience with our account managers, Ben, Lansard, and Garrett, has been exceptional. The service has been outstanding.
I would rate their customer support a ten out of ten.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We had no application whitelisting platform prior to ThreatLocker.
How was the initial setup?
The agents are on-premises. The deployment of ThreatLocker agents has been very smooth and clean. Our challenge has been the maintenance of the accounts. As devices go offline and are retired, there are no automated falloff methods, and that has caused some challenges for us.
What about the implementation team?
We had a sales engineer provided by the ThreatLocker team to assist us. I want to specifically acknowledge Garrett, our second sales engineer, who made the product work effectively and built our trust and confidence in ThreatLocker.
What was our ROI?
It is less about a tangible dollar return on investment and more about risk management and peace of mind for both our MSP and our clients. Feedback from technically inclined clients indicates that having this solution in place allows them and their teams to feel secure, helping us all sleep more soundly at night. For an MSP, it has been one of the most effective solutions.
What's my experience with pricing, setup cost, and licensing?
We have encountered a few challenges regarding pricing, contract renewals, and additions. As we explored adding features like Cyber Hero, it proved to be an increased expense for our clients. This was primarily a mistake on our part due to how we initially priced it to clients. After conversations with other partners, it became clear we underpriced it initially, which caused most of our issues, rather than any fault with ThreatLocker.
Which other solutions did I evaluate?
We evaluated multiple solutions beforehand such as SentinelOne, CyberFOX's AutoElevate solution, and others. We evaluated these options before adopting ThreatLocker and continue to reevaluate them annually, but ThreatLocker has consistently remained in our stack because they do it right. ThreatLocker stands out because they understand application whitelisting and elevation controls deeply, addressing real issues effectively.
A lot of companies get into application whitelisting and elevation control, but they lack a true understanding of the real issues and how to properly address them. ThreatLocker does a great job of knowing what they do well, and in a good way, staying in their lane and excelling at what they do. A lot of the other people who have similar products either are vastly overpriced or try to do it all. When you try to do it all, you end up not doing it all well. ThreatLocker excels in knowing its strengths and not overextending.
What other advice do I have?
I would rate the product a nine out of ten. More emphasis on the business aspects, such as billing and portal administration, would push the rating to a ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partnership