A Zero Trust operating model for modern legal work

CIO of Rumberger Kirk Avi Solomon runs a deny-by-default environment. His team needs to block untrusted executables and scripts, prevent privilege creep, gain visibility into misconfigured processes and vulnerabilities, and protect sensitive client data.

To do this, Solomon deployed ThreatLocker capabilities:

  • Application Allowlisting
  • Ringfencing
  • Priveleged Access Management
  • EDR Real-Time Threat Detection
  • Managed Detection and Response
  • Data Storage Access Control
  • Centralized Configuration Management

One morning, an attorney tried to launch a utility they had downloaded without approval. ThreatLocker blocked the executable and logged the attempt in the console. No investigation cycle, no cleanup, and no chance for lateral movement. Here’s how it happened:

  • Application Allowlisting stops untrusted execution
    Solomon describes Application Allowlisting as the foundation of his defensive posture because it stops untrusted code before it can ever run.
  • Ringfencing contains a trusted tool behaving badly
    A legitimate application started to access files outside its normal working directories. Ringfencing kept it within its allowed paths, so the application continued to function while the unnecessary access was blocked. For Solomon, this is standard practice. Applications run only within clearly defined boundaries.
  • Privileged Access Management eliminates privilege abuse opportunities
    A vendor needed to run an administrative utility on an attorney workstation. In Solomon’s world, no one receives blanket local admin rights. He approved elevation for the specific tool only. The task completed. The environment stayed clean. This single shift eliminates an entire category of attack surface.
  • Data Access Storage Control protects high sensitivity case data
    A misconfigured workflow attempted to access protected legal matter directories, and ThreatLocker blocked the action immediately. The system logged the denied attempt, giving Solomon the visibility he needed without exposing the firm to data leakage. For a legal CIO, this is non-negotiable.
  • EDR identifies anomalous behavior in real time during a live issue
    During an otherwise normal day, EDR surfaced a suspicious pattern of child process spawning in real time. Solomon used the telemetry to identify the source, isolate the behavior, and validate that no compromise occurred. ThreatLocker EDR Real-Time Threat Detection adds an additional layer of context above prevention, which Solomon relies on for fast decision making.
  • Cyber Hero MDR provides rapid analyst support
    During a particularly noisy alert sequence, Solomon engaged Managed Detection and Response (MDR) to validate and interpret the event. The team responded within minutes, confirmed the threat level, and guided next steps. MDR acts as a force multiplier for a CIO managing a distributed legal environment.

Hear from Rumberger Kirk

ThreatLocker Zero Trust Platform

How GB Tech averted a breach from leading to disaster with ThreatLocker

Explore the case study for an in-depth breakdown of how GB Tech’s Director of Information Technology was able to avoid a breach thanks to the quick response of the ThreatLocker Managed Dectection and Response (MDR) team.

Keep your environment secure with Zero Trust controls

Request a demo