Insights › Essential Eight

What Is Application Control? A Guide for Business

Conceptual illustration of a gate allowing only approved application blocks through on a navy background.

Most cyber security advice tells you to block the bad stuff: install antivirus, filter dodgy emails, keep a blocklist of known threats. Application control turns that thinking on its head. Instead of trying to recognise every piece of malicious software in the world (an impossible task, given attackers write new variants every day), it flips the question around and asks a much simpler one: is this program on our approved list? If the answer is no, it does not run. Full stop.

It is one of the eight controls in the Australian Signals Directorate’s Essential Eight, and it is widely regarded as one of the most effective things a business can do to stop malware and ransomware in their tracks. It is also one of the least understood. This guide explains what application control is, how it works, and how an Australian small or medium business can start using it without grinding day-to-day work to a halt.

What is application control?

Application control is a security approach that restricts which software is allowed to run and install on your computers. In the words of the ASD, it makes it “harder for users to intentionally or unintentionally install unwanted or malicious software”. Rather than letting any program launch and hoping your antivirus catches the dangerous ones, application control only permits software you have explicitly approved.

That approval covers more than just the obvious .exe files people double-click. A properly configured application control policy governs executables, software libraries (the DLL files programs rely on), scripts, installers, compiled HTML, HTML applications and control panel applets. Attackers use every one of these as a way to get code running on a machine, so controlling all of them, not just the headline program files, is what makes the approach so hard to slip past.

Allowlisting versus blocklisting

To understand why application control is so powerful, it helps to compare the two ways you can decide what software runs.

A blocklist is a list of things that are not allowed. Traditional antivirus works this way: it keeps a catalogue of known-bad files and stops them. The trouble is that the list can only ever contain threats someone has already discovered and named. Brand-new malware, or a slightly modified version of something old, is not on the list yet, so it sails through.

An allowlist (sometimes called allowlisting) works the opposite way. It is a list of things that are allowed, and everything else is blocked by default. You do not need to know what tomorrow’s malware will be called, because it was never on your approved list in the first place. This is the model application control uses, and it is why the approach protects you against threats no one has seen yet, the ones a blocklist can never catch in time.

What application control actually stops

The value of application control becomes obvious when you look at how most breaches begin. A staff member opens an email attachment, clicks a link, or downloads a file that turns out to be malicious. On an unprotected machine, that file runs and the attacker gets a foothold. With application control in place, the malicious program is not on the approved list, so it simply cannot execute; the attack fails at the first step.

In practice, a good application control setup blocks things such as:

Because ransomware depends on getting an executable to run, application control pairs naturally with a solid backup strategy. Control stops most attacks reaching your files in the first place, and good backups mean you can recover if anything ever slips through. If you have not sorted your backups yet, our guide to the 3-2-1 backup rule is the place to start.

Where it fits in the Essential Eight

Application control is not meant to stand alone. It is one layer in the Essential Eight, the Australian Government’s baseline set of mitigation strategies for stopping common cyber attacks. It works alongside the other controls rather than replacing them.

The most natural partner is patching. Application control decides which programs are allowed to run; keeping those approved programs up to date closes the security holes attackers exploit inside software you genuinely need. The two go hand in hand, which is why prompt updates matter so much; we cover the reasoning in why software updates matter. Restricting who has administrator rights, blocking untrusted Microsoft Office macros and hardening user applications all reinforce the same goal: shrinking the number of ways malicious code can get a start on your systems.

How to start without breaking everything

The biggest fear owners have about application control is understandable: what if it blocks a program the team actually needs and stops people working? That fear is exactly why the recommended approach is gradual, not a big-bang switch-on. The ASD’s own guidance suggests running it in monitoring mode first, so you can see what would be blocked before anything actually is.

A sensible rollout for a small business looks like this:

  1. Take stock of what you use. Make a list of the software your team genuinely relies on day to day. This becomes the foundation of your approved list.
  2. Turn on audit mode. Deploy the policy so it records, but does not block, anything that falls outside the approved list. Let it run for a few weeks across real work.
  3. Review the logs. Look at what got flagged. You will usually find a handful of legitimate business apps that need adding, and a lot of noise you are glad to be rid of.
  4. Add the exceptions, then enforce. Once the approved list reflects reality, switch the policy from monitoring to blocking. Now anything not on the list is stopped.
  5. Keep it current. Review the list when you bring on new software or new staff, so approvals keep pace with how the business actually works.

If your business runs on Windows, you may already have the tools for this. Microsoft’s App Control for Business (previously known as Windows Defender Application Control, or WDAC) and AppLocker are built into the platform, and App Control can lean on Microsoft’s reputation data, its Intelligent Security Graph, to automatically trust well-known, reputable apps so you are not approving every single program by hand. Businesses on Microsoft 365 Business Premium already have access to these capabilities. If managing this yourself feels daunting, this is a very reasonable thing to hand to an IT provider.

The honest limitations

Application control is powerful, but it is not magic, and it helps to be clear-eyed about what it does not do. Its main blind spot is dual-use software: programs that have legitimate uses as well as malicious ones. Remote access tools are a classic example. If a program is genuinely useful and therefore on your approved list, an attacker who tricks a staff member into misusing it can still cause harm. Application control will not save you there, which is why staff awareness and the other Essential Eight controls still matter.

The other honest caveat is effort. Application control takes more setup and ongoing care than simply installing antivirus and forgetting about it. You have to build the approved list, test it, and keep it up to date. For most Australian businesses that trade-off is well worth it, because the protection you get, stopping malware and ransomware before they can run at all, is among the strongest available for the money.

Find out where you stand

Application control is one piece of a bigger picture, and the best way to know whether it should be your next priority is to see how your whole security posture stacks up. Our free self-assessment walks you through 27 short questions and maps your answers to the Essential Eight, ISO 27001 and SOC 2, then gives you a personalised PDF report showing exactly where you are strong and where to focus next.

It takes about five to ten minutes, it is completely free, and you get your report instantly. Take the free assessment and find out where your business stands today.

Discover more from Security Score

Subscribe now to keep reading and get access to the full archive.

Continue reading