A Zero Trust operating model for modern legal work
CIO of Rumberger Kirk Avi Solomon runs a deny-by-default environment. His team needs to block untrusted executables and scripts, prevent privilege creep, gain visibility into misconfigured processes and vulnerabilities, and protect sensitive client data.
To do this, Solomon deployed ThreatLocker capabilities:
- Application Allowlisting
- Ringfencing
- Priveleged Access Management
- EDR Real-Time Threat Detection
- Managed Detection and Response
- Data Storage Access Control
- Centralized Configuration Management
One morning, an attorney tried to launch a utility they had downloaded without approval. ThreatLocker blocked the executable and logged the attempt in the console. No investigation cycle, no cleanup, and no chance for lateral movement. Here’s how it happened:
- Application Allowlisting stops untrusted execution
Solomon describes Application Allowlisting as the foundation of his defensive posture because it stops untrusted code before it can ever run. - Ringfencing contains a trusted tool behaving badly
A legitimate application started to access files outside its normal working directories. Ringfencing kept it within its allowed paths, so the application continued to function while the unnecessary access was blocked. For Solomon, this is standard practice. Applications run only within clearly defined boundaries. - Privileged Access Management eliminates privilege abuse opportunities
A vendor needed to run an administrative utility on an attorney workstation. In Solomon’s world, no one receives blanket local admin rights. He approved elevation for the specific tool only. The task completed. The environment stayed clean. This single shift eliminates an entire category of attack surface. - Data Access Storage Control protects high sensitivity case data
A misconfigured workflow attempted to access protected legal matter directories, and ThreatLocker blocked the action immediately. The system logged the denied attempt, giving Solomon the visibility he needed without exposing the firm to data leakage. For a legal CIO, this is non-negotiable. - EDR identifies anomalous behavior in real time during a live issue
During an otherwise normal day, EDR surfaced a suspicious pattern of child process spawning in real time. Solomon used the telemetry to identify the source, isolate the behavior, and validate that no compromise occurred. ThreatLocker EDR Real-Time Threat Detection adds an additional layer of context above prevention, which Solomon relies on for fast decision making. - Cyber Hero MDR provides rapid analyst support
During a particularly noisy alert sequence, Solomon engaged Managed Detection and Response (MDR) to validate and interpret the event. The team responded within minutes, confirmed the threat level, and guided next steps. MDR acts as a force multiplier for a CIO managing a distributed legal environment.