Citadel targets smaller organizations that do not have the budget or know-how to install and maintain a one or more security solutions. However, regular end-users can use the installer to install Citadel, even outside the scope of an organization. In this case Citadel will remind instead of enforce, and you get most of the security benefits of Citadel, such as detection of bad domains, phishing, inadvertent pasting of secrets, or use of bad passwords.

Installing Citadel is relatively straightforward. There are a few moving parts: Citadel installs in the browser, on the OS, and —optionally— in your SIEM. There are sensible defaults, the installer takes care of everything except integration into your SIEM, and this guide walks you through each step. SIEM integration is only needed if you want logging, alerting, and centralized dashboards.

If you are installing Citadel as an administrator, check out the configuration manual to understand how you can adapt Citadel to your organization, for example by configuring your logo, name and support e-mail address. Don’t forget to tell Citadel what your domain and official applications are, so that Citadel will take extra care of those, and users do not get false “shadow IT” warnings.

There is also the human side: users will at times be interrupted, warned or blocked; IT policy will likely be applied more strictly than it was before. Citadel takes great care to respect the privacy and agency of your users. Even so, deploying Citadel will undoubtedly raise questions around privacy. Depending on your organizational culture, this may need some preparation and communication ahead of the rollout. The privacy section provides useful templates for compliance with privacy legislation, along with answers to frequently asked questions, to help you deal with all of this.


Table of contents