Featured by Newsweek & World Class Media Outlets
Danny Jenkins

Danny Jenkins

CEO & Co-Founder
ThreatLocker
16 July 2026

ThreatLocker is a cybersecurity company that provides Zero Trust endpoint protection solutions designed to prevent unauthorized software, ransomware, and other cyber threats by allowing only trusted applications and actions to run.

You've spoken about AI as both a powerful tool for cybersecurity and a weapon for attackers. What AI-related threats do you think business leaders are still underestimating?

There are really two major risks. The first is that attackers are adopting AI faster than businesses understand it. AI can generate previously unseen malware, create convincing voice phishing, and produce realistic fake videos.

The technology itself isn't the biggest problem—it's that people still trust what they see and hear. Just as we learned not to automatically trust emails, we're now entering a world where we can't automatically trust voices or videos either.

The second concern is AI itself acting inside an organization. Unlike traditional software, AI doesn't have to be vulnerable to make bad decisions. We've demonstrated prompt injection attacks where AI agents encrypted files, uploaded data to the internet, and deleted files after being manipulated. Companies are effectively introducing a new entity into their business that has access to sensitive data and can either make mistakes or be tricked into making them. That's why organizations need strong controls around AI agents.

You've suggested that AI mistakes are becoming a cybersecurity issue in their own right. Why is that?

The line between operational continuity and cybersecurity is becoming increasingly blurred. Security isn't just about defending against attackers—it's about ensuring the business continues to operate. AI assistants are designed to anticipate what users want, but that same capability can create unintended consequences if they make the wrong assumptions.

For example, an AI agent might automatically upload sensitive reports because it assumes that's what you've done previously, inadvertently exposing confidential customer information. Whether that's a security issue or a continuity issue is almost irrelevant—the damage is real. Organizations now need cybersecurity controls that can prevent accidental AI-driven data loss just as effectively as deliberate attacks.

Should CEOs now take personal ownership of AI cybersecurity?

Yes, I’d say so. In most organizations, business leaders still need greater awareness. Technology companies and banks generally understand these risks because technology sits at the heart of their business. But many manufacturers, airlines, hospitals, and other traditional industries are still led by executives whose backgrounds aren't in technology, making them less likely to appreciate how quickly the threat landscape is changing.

The challenge is that many organizations only act after something goes wrong. It's no different than installing sprinklers after a building has already burned down. Companies need executive-level understanding before a major incident occurs, because once it does, it's already too late.

Many cybersecurity companies advocate a Zero Trust model. What differentiates ThreatLocker's approach, and how do you balance security with productivity?

Zero Trust is often misunderstood as adding friction, but its real purpose is least privilege—giving users and applications exactly the access they need and nothing more. It's never about preventing people from doing their jobs. In fact, it often improves productivity because users are less likely to be disrupted by security incidents.

A good example is authentication. Instead of trusting only usernames and passwords, we also validate the device. Even if someone steals your credentials, they still can't access your account without a trusted device. That means users aren't constantly locked out while security teams investigate compromised accounts. The same principle applies to malware and AI: instead of trying to identify everything that's malicious, we simply allow what's required and block everything else, dramatically reducing the potential impact if something goes wrong.

How widely has Zero Trust been adopted?

Adoption is still very limited. Only a small percentage of organizations have fully implemented device validation and stronger cloud controls, while even fewer default-deny software execution or apply strict policies around AI agents. Those numbers are growing rapidly, but they're still low.

The biggest concern is that AI adoption is moving much faster than the security controls needed to govern it. Organizations are embracing AI before they've put the proper safeguards in place, creating a widening security gap.

What was your reaction to the Mythos experiment, and what does it tell us about the future of AI-powered cyber threats?

Technology will continue advancing whether we're ready or not. If one organization doesn't release a capability, someone else eventually will. In many ways, Mythos simply highlighted a problem that's already here. Today's AI models are already finding vulnerabilities that humans would likely have missed, and we've seen the number of software vulnerabilities rise dramatically in recent years.

My concern is less about the existence of these tools and more about restricting access to them. If software developers can't test their products against the same AI capabilities attackers can use, they'll always be behind. The strongest defense remains restricting what software can do and ensuring systems are patched quickly, but developers also need access to advanced tools to strengthen their own products.

With AI evolving so rapidly, what’s your strategy for ThreatLocker staying ahead?

One advantage of Zero Trust is that we're not trying to predict every new threat. Whether malware is created by AI or a human is largely irrelevant. By adopting a deny-by-default approach—trusting only what's required and blocking everything else—we're already positioned ahead of many emerging attack techniques.

Our biggest focus is adapting to how legitimate AI applications work. AI requires more dynamic permissions than traditional software, so we've had to innovate quickly to ensure organizations can safely enable AI while limiting unnecessary access. Internally, we're also focused on responsibly adopting AI ourselves while ensuring we continue developing the human expertise needed to build secure products. AI is an incredibly effective tool, but experienced engineers remain essential because software still requires judgment, creativity, and accuracy that AI alone can't consistently provide.

Where do you see the biggest opportunities for ThreatLocker, and which industries still have the most ground to make up?

Cybersecurity has become a challenge for every industry. Our customer base spans aviation, financial services, manufacturing, healthcare, technology, and many others, with no single vertical representing more than 20% of our business. While sectors such as government and large financial institutions are generally further ahead, most organizations—and many executive teams—recognize they still need to catch up.

From a geographic perspective, we're continuing to expand globally. We now have offices in the U.S., Ireland, Dubai, and Australia, with London opening shortly and Singapore representing another important opportunity. Ultimately, our goal is simple: to protect as much of the world as possible by continuing to expand into new markets as we grow.