Organizations have almost universally deployed endpoint security, yet with less than stellar efficacy against advanced attacks. Next-Generation endpoint solutions are struggling with algorithmic-based models of past ‘bad’ behaviors, to predict the next unknown attack or unknown vulnerability. The advent of modern phishing campaigns, fileless malware, nation-state tool kits, and new vulnerabilities, highlights the need for a fresh look at OS-Centric Positive Security Models to protect data on endpoints.