LOCAL
BUSINESS
Cloud Threat Protect by TrustLayer
Log a deal
Two products, one story

ETP vs CTP:
two layers, not a choice.

They protect different things. One guards the device; the other controls the risky activity that puts the device at risk. Your customer needs both — here's how to say why.

The line ETP guards the device. CTP controls the activity that puts the device at risk. Back to objections →
Defence in depth, not either/or

Where each one fires

CTP reduces how often ETP ever has to fire. ETP is the safety net for anything that gets through.

01
Step 1 · The user acts

A click, a site, an upload

Someone clicks a link, visits a risky site, or uploads data to an unsanctioned cloud app. This is where most breaches begin.

02
Cloud Threat Protect

Stops it at the source

Blocks the phishing link, the malicious or risky domain and the unsafe upload — and surfaces shadow IT before anything reaches the device.

03
Endpoint Threat Protect

Protects the device

If a threat still reaches the device, ETP detects, prevents and responds — isolating it, killing the process, quarantining the file.

Remove either layer and you leave a gap the other was never built to cover.

What ETP doesn't do

Seven gaps, and how CTP closes each one

ETP protects the device. It's not built to control what users do online — and that's exactly the gap CTP closes.

ETP doesn't reveal shadow IT
CTP discovers and reports it across the business
ETP doesn't show what users are doing online
CTP gives full web and cloud usage visibility
ETP doesn't apply web or cloud policy by user, group, device, location or risk
CTP enforces granular, identity-aware policy
ETP doesn't control uploads, downloads or data movement to the cloud
CTP applies data controls to web and cloud activity
ETP doesn't block risky or malicious websites at the point of click
CTP filters web traffic and blocks risky domains in real time
ETP doesn't stop phishing links in email before they're clicked
CTP checks links and blocks malicious URLs at the moment of click
ETP doesn't control which cloud apps and SaaS staff can use
CTP governs sanctioned and unsanctioned cloud use

Side by side

Endpoint Threat Protect compared with Cloud Threat Protect
Aspect Endpoint Threat Protect ETP Cloud Threat Protect CTP
Centres on The device The user, and what they're doing
Stops Malware, ransomware, malicious processes and exploits on the machine Phishing, malicious or risky websites, unsafe uploads and downloads, shadow IT and risky or unauthorised SaaS use
Acts On the endpoint, once a threat has reached the device At the point of use, before the user reaches the threat
Strongest at Isolating a compromised machine, quarantining files, killing processes, forensic response Controlling web, email and cloud activity; visibility of shadow IT; policy by user, group, device, location or risk score
Doesn't do Control web, email or cloud activity, or reveal shadow IT Replace AV or EDR, or do device-level malware response

When a customer asks “why both?”

“Endpoint Threat Protect protects the device — it's the safety net if something malicious lands on the machine.”

“Cloud Threat Protect works a step earlier. It stops your people reaching the malicious link, site or cloud app in the first place, and gives you visibility of shadow IT and risky data movement.”

“One guards the device, the other controls the activity that puts the device at risk. That's why they sit together — not instead of each other.”

Landed the CTP alongside their ETP?

That's the conversation this page exists for. Log the order while the number is still in front of you — the five working days run from the order date, not from when you remember.

Log a deal →