Block Everything and Get Your Life Back
Ransomware recoveries taught Danny Jenkins that reactive security has an expiration date. Danny, CEO and Co-Founder of ThreatLocker, joins Alan Shimel on Techstrong TV to explain why default-deny zero trust is the only architecture that scales against modern threats — and how AI is dramatically accelerating both sides of the fight. Danny walks through the origin story of ThreatLocker after a Sydney ransomware cleanup, the mechanics of application allowlisting and ringfencing, and the everyday attack vectors most IT teams still underestimate: coupon-clipper browser extensions with keylogging permissions, Rubber Ducky USB devices that impersonate keyboards, and rogue peripherals that quietly hand over the network. He also gets candid about the geopolitics of AI — including new Chinese models, US export controls and the fear of state-sponsored backdoors — and shares the three vectors defenders should be locking down first. His parting advice: block everything, then allow only what your business actually needs.
Transcript
Hey everyone, welcome back here to Techstrong TV. Our next guest is a guy in Florida. I love when we get people from Florida.
We don't get very many people from Florida on our show. His name is Danny Jenkins, CEO and co-founder from ThreatLocker, and I know what you're going to say. He doesn't sound like he's from Florida, but he's been here a while.
Let's welcome Danny to the show. Hey, Danny. Nice to meet you.
Nice to meet you too, Alan. Thank you for inviting me today. So I gave you the perfect setup to give us a little bit of your life story.
How'd a guy with this accent wind up in Florida? So I actually just moved here because I wanted to. I grew up in the UK.
I left school at 15. Loved technology, loved pulling apart computers. Got into IT by the time I was 16.
I was building network servers for the government in the UK, local governments, and then ended up working corporate IT. Well, I moved to Ireland and then ended up working corporate IT when I was 19 and just ended up getting into security, and one day I was just kind of fed up. " And we just got on a plane and moved to Florida.
God bless you. That's great. Well, I moved down, if you couldn't tell, I don't have a Florida accent either.
I'm from New York, but we're down here about 23 years now, I think. And similar, well, it's a funny story. I was starting a security company in Boulder, Colorado, and we were going to move to Boulder, but somehow wound up in Florida, too.
The weather did it. The weather doesn't suck, as they say, so it was a big draw. But yes, you're up in Orlando, of course.
I'm a little further down south. But Danny, along the way here, you're CEO, co-founder of ThreatLocker. Tell us the whole ThreatLocker genesis story, if you don't mind.
So, I'd had multiple email security companies, and I'd sold the last one, it was like 2014, and I'd sold it to a customer. " So we make an agreement. If I get in, if I can gain full access, then we show you your weaknesses, and we'll show you how to fix them.
But I ended up doing more ransomware recoveries because people would just keep calling me saying, "Hey, I've got this client hit by ransomware. " And I remember one in Australia, an Australian IT company called me to help with the recovery. So they paid a ransom, didn't get their data back.
Right. And it was an insurance broker, 50 employees maybe, and I just start working through this ransomware, and at the end of the conversation, we get it up and running. Really tough, by the way, because all the backups are gone, everything is gone.
" I said, "Just block everything. " The IT company told the owner I was nuts, and it was impossible. " So I tried to find products, couldn't, and said, "You know what?
Ransomware is becoming such a big issue. " It wasn't called zero trust back then, but denying by default, simple, whether it's blocking software, making sure ports aren't open on firewalls and only opening them when they're needed, elevation controls, ring-fencing apps. " And that's what we set off to do, and it was 2017.
Today, we have some of the biggest companies in the world, well, the biggest companies in the world as customers, but we also support small businesses through MSPs right up to airports and airlines and other types of organizations. What a great story, man. That's fantastic.
And you're right. Look, we didn't call it cyber, we called it security. I've been in security 25 years, tech longer, and I tell people that all the time, too.
You want to really be secure? Unplug it from the internet. That'll keep you secure.
You may not do much business, but at least you'll be secure. And then put realistically just turn things on one at a time as you need it, and don't leave it on if you don't need it on. Turn it on as needed, shut it off as needed, so that lessicity that we preach with the web.
Of course, now we do call it zero trust, and it's a little bit more well-settled about how to go about doing it. We just did it here in our com- and we're a small company, but when the open clause stuff started coming out and people were experimenting. " But let's be smart about it.
So we built some cages. You had to have it on a dedicated box, a Mac Mini or something. It had to be running on a VM, excuse me, on top of that.
And then we started with a very zero trust attitude and just turned on what it needed when it needed it, and back off again. And that's really it. The thing is- You're not going, yeah ...
AI is fantastic, but it's so powerful. And AI is just one example of an application. If you give it loads of power and you hear about, oh, it accidentally deleted a production database.
It can accid- ... endly email data, upload data. " So just limiting what it can do, making sure it can't see all your files, and whether it's through a VM or whether it's through what we call ring fencing, which is just give the permissions to the files as they need it, and only for what they need.
Limit how many files, limit what websites it can go to. And the user experience is still they do their job, everything's working fine. No, it does what you need.
So along those lines, it's similar to what we did. Instead of giving you access to my G Drive, I'm just going to give you access to this folder on the G Drive where I put those documents that I want the agent to work on, or work with, or have access to. And they can't send it out.
I don't have to tell you, you do this for a living. The problem is, first of all, I think as companies get bigger, it becomes harder to impose those kinds of policies and processes without something like a threat locker, right? Yeah.
And that's really it. As an individual, it's very easy to control things. As a company, you need tools and you need automation, you need learning, you need to understand predefined policies and organization policy.
And I'll be honest, you need to understand that some people aren't going to follow the rules, and you've got to be able to enforce the rules, right? Because that's the other thing. This isn't my first rodeo either.
You tell people, "This is what you need to do," and then people do what they want to do, right? And they don't always follow the rules. " And that's an important part of it, too.
Even things like browser extensions, like users just downloading any browser extensions they want, and it's like you didn't realize this browser extension was made in China. It's a coupon clipper. Right.
" And look at the permissions it has. It can see every password for every website you enter. Who looks at the permissions?
And that's why sometimes you just got to say, "I'm enforcing a rule of no extensions unless IT approves it," versus- And that's me ... right? " We did the same with keyboards in our office, like no keyboards unless approved by IT, because people were bringing in cheap wireless keyboards that could be intercepted and almost- Yeah ...
rubber ducky through a keyboard. Look, I remember the day. So one of the companies I had started, security company, we did a lot of work with DoD.
We get the call from the DoD. So we made a NAC, network access control, right? We check- Yeah ...
devices before they come on. " I said, "Yeah, you could probably write that check. That's fairly easy.
You're just looking at the configs. " Well, we found out years later of the story of the Chinese, or allegedly the Chinese, throwing USB drives into the parking lot of the Pentagon, and people picking them up and bringing them in and plugging in the... The story goes, the stealth fighter plans might've been stolen with that.
And that's why they were doing it. It's crazy stuff, but true. It's interesting because we do these rubber ducky challenges at events we go to.
Uh-huh. We're in Dublin one day, and we always do as a joke, "Hey, I've got a deal. " And then I change it and say, "I'll change the odds.
If it doesn't steal your data, we're going to fly you to our conference in Orlando, security training for three days. " So I've got like 15 people in a row coming up, plugging this rubber ducky into their machine. Right.
Like with some of the best EDRs and antiviruses. " I said, "If you block USB ports, you're about to win a trip to Florida. " And he plugs in the rubber ducky, it sends keystroke.
Boom. Throws up PowerShell, exfils all the data. No, the Pentagon shut the drives.
Not the drives, the ports themselves. Yeah. They had to be disabled.
Hot glue. But the story you tell, Danny, reminds me of an old thing, right? So they wouldn't do it just to win a rubber ducky, but for a trip to Florida, they do it.
So I know what you are, it's just a question of the price, really. ai, some of us call it GLM52. If you're not familiar, of course, this is a Chinese AI model, right?
Yes. Generative AI model. I believe it's still at least somewhat open source, correct?
As of now, yes. Or nominally? Yes.
Unless you ask it the wrong questions. Right. Well, no different than the rest of the so-called Chinese open source AI models.
But the interesting thing about this GLM52 or ZAI is they're claiming it's kind of on par with Mythos. It's interesting. We've been talking about blocking the export of Mythos and AI models, and I don't think it makes any difference.
And I think trying to control it, first of all They're just going to come into the US, use a US server, set up a US company, get the software, export it out. It's going to happen. So- I think it already happened is the issue, but and that was why the original blockage of Mythos was they were trying to block foreign nationals in the US from using it.
How the heck, what am I supposed to do? Check your passport before you log on? I mean- Well, also, why wouldn't one US national get, realistically, $500?
" Or I'll give you a free trip to Orlando, right? What else is it going to take? So- I get it ...
it is terrifying. And it's funny because I've been looking at AI against vulnerabilities, and AI is fantastic at finding vulnerabilities. It's fantastic at doing code reviews, reverse engineer, finding weaknesses fast.
Humans can too, but it's just faster. And then it's also fantastic at creating malware that's never been seen before. " And it won't even get detected.
And the nice thing, the terrifying thing is now you've got all these models, and it's getting worse and worse and worse. And companies, they're scrambling. " It's like, well, you can't determine intent.
You can only determine a behavior. You know what? I file this under why we can't have nice things.
Because you want a powerful AI to do all of the great things that AI could do. And make no mistake, AI could do some great, unbelievable things and really help in your business. But there's the other side of the same coin, which is exactly what you're talking about, the things it could do in the wrong hands with the wrong intent.
And I also agree with you, Danny. I think trying to stop with export controls and everything is like grabbing sand in your hand. The tighter you squeeze it, the more it runs out.
And I don't pretend to know the answer. Let me say that out loud, too. I don't know what the answer is, but I know the genie's out of the bottle.
Right? And I don't know. I don't think you could put it back.
No, it's out of the bottle. And the problem is we just have to adapt as a world- Yep ... fast.
And it's the same. We got attacks on 9/11. The world adapts.
We have big security machines going through the airport. Everyone's vetted. And unfortunately, we adapt too late.
And that's what's happened with AI. People are adapting too late. We know now that malware can be created, undetectable vulnerabilities.
We have more zero days in the last two months than we've seen in years. And- No surprise, right? And yes But there are solutions, but the problem is you have to take them, and you have to just say, "This is the world we live in now.
" The problem is everyone's just too busy talking about how terrifying it is rather than just doing basic things to make their lives better. Yeah. So let's take a minute.
Look, I'm a security guy. You're a security guy. We're both kind of geeky talking about this stuff at expert level maybe, right?
But there's people out here who maybe they're software developers or platform engineers or just general IT people who don't have that level. What are some of the basic things we could do to help? So I think there's three ways you're most likely to fail right now as an IT manager, as a cybersecurity person.
There's three ways an attacker's going to get onto your system, and it's just very simple. They're going to come in through an open network port, they're going to come in through running software, or they're going to come in through phishing you and gaining access to a token of some description. They're the three things that are hitting everyone.
So as a user, you can check everything before you click on the link. You can make sure you don't run software. The ports is a little bit trickier for a user to understand what's open on their machine.
As an IT professional, you can say, "I'm going to validate the device, not just the username, password, and authentication token, because that way if a token gets stolen, they can't gain access. So I'm going to use some kind of zero trust network access or cloud access or things to validate that it's coming through a legitimate source and not stolen. I'm going to stop on trusted software.
And the stuff I'm going to allow, I'm going to limit what it can do using some kind of ring-fencing, whether it's AI or anything else. " So it's not magic. It's just these are steps we can take today that will make a huge difference on the probability in attacks.
And I wish we could rely on the user, but you can't. Like it's impossible to rely on. Whether it be through they didn't understand, they were busy, or they just don't care.
Intentional or not intentional, you just can't rely on them. Yeah. I do agree with you.
And I think that, unfortunately, is the best we can do right now. And I also think you mentioned a few different periods of things with the world we've gone through in the world. We're going through this adjustment period now where I think best practices will emerge, and people will hopefully be better, do better at doing it.
But I also think when we look at this whole AI and the open source and everything, I don't know if you saw the Chinese now claim that there was a backdoor built into Mythos That checks specifically if you came from a Chinese IP or not. And now Anthropic admitted that back in May, they did have that, May or March, a month within then, they did have that built in. Maybe it was part of the government asking them to check for if who was using it, but that they took it out in June or July.
Right? So there's all of this, it's like FUD, right? Uncertainty and doubt being sown around all the, not just the Chinese models, but the US models.
And I think, look, the models are incredibly powerful and the power is-- Well, the problem is they're as powerful as the smartest humans, also the dumbest humans sometimes as well. Yeah. But they can do...
And I think, we use it for various code reviews and building and things like that. Mm-hmm. But it doesn't deliver the accuracy you want, but it can do it so much faster.
And we essentially have, like anyone in the world right now has access to 5,000 senior software engineers to write a piece of malware. And that's the terrifying thing. There's six plus billion- It is ...
people with access to computers. But by the same thing, they also have access to 5,000 to 6,000 software engineers to write their next app or help them write their next. I had one of my AV people ask me yesterday, should he go look for an online training class for best practices in posting video, this is real life, posting videos to YouTube, to get best SEO, AEO, and widest exposure.
I said: "Why would you go pay for a class for that? " And he was like, "Oh, yeah, you're right. " That's the good side of AI, right?
It can teach you all these great things. The bad side is it could also write the malware that's going to bring down your whole system or- And it will teach somebody else too. So we're all on the same playing field.
We've also only got super power. Crazy times, man. It's how we use them.
That's exactly it. And it still comes down to who's behind the keyboard and what their intents are, intentions are. Yeah.
Anyway. Hey, Danny, I understand you're going to be a black hat in a few weeks with ThreatLocker. Yes.
People- I think I'm doing a presentation on AI showing literally some AI tools, the commercial ones, encrypting entire systems, just through a few prompts. Oh, that's fun. All right.
I may have to come check it out then. Hopefully, we'll see you out there. I'll be the one sweating because it's 115 degrees.
But nah, it's cool. They got the AC on at Mandalay Bay. I won't be leaving the hotel.
I'll go- You and me both. I learned that lesson. Three years ago, we co-sponsored a party at the pool.
I spent the entire party under one of those misters saying I'll never, ever, ever do that again. But thank you for coming here on Techstrong TV. We appreciate it.
Keep up the great work at ThreatLocker, man. As I said, it's interesting times we're living in now. We need this kind of common sense and real best practices approach to trying to keep as safe as we can.
And hopefully, we'll see you in Vegas, and we'll catch up there. Look forward to seeing you in Vegas. Thank you.
All right. Danny Jenkins. Danny Jenkins, CEO, Co-founder, ThreatLocker, here on Techstrong TV.
We're going to take a break. We'll be back in a bit.