25 Aug 2026
Signal Headquarters
Vol. I
No. 237
Organization

What is ThreatLocker?

ThreatLocker is a cybersecurity company that provides a zero-trust application whitelisting platform. In December 2025, CEO Danny Jenkins discussed the company’s approach to ransomware defense and customer onboarding, while Jack Rhysider described how attackers pivoted away from ThreatLocker-protected Windows devices.

Company timeline

  • Dec 2025 - Danny Jenkins said he has never had a customer with a ransomware case that wasn’t ignoring obvious signs.
  • Dec 2025 - Danny Jenkins said that for ninety percent of customers, they’re starting from a clean slate.
  • Dec 2025 - Danny Jenkins said that seventy to eighty percent of support tickets have nothing to do with ThreatLocker.
  • Dec 2025 - Danny Jenkins said he has onboarded people in hours.
  • Dec 2025 - Jack Rhysider said that attackers, finding ThreatLocker on Windows devices, pivoted to other parts of the environment lacking it.

Where it appears in the record

Every line below is attributed to a named speaker.

Contrarian take

Attackers encountering application whitelisting on protected endpoints do not give up but pivot immediately to unprotected systems on the same network, meaning partial zero-trust coverage can redirect rather than stop attacks.

“They quickly realized that ThreatLocker was on the Windows devices, so they knew that they wouldn't be able to use those for the purposes that they intended, and they began to pivot to other locations in the environment that did not have ThreatLocker.”
Jack Rhysider · 23 Dec 2025
Worth quoting

Danny Jenkins on ransomware victims at ThreatLocker's customer base, observing a consistent pattern of ignored warnings.

“I have never had a customer with a ransomware case that wasn't ignoring obvious signs.”
Danny Jenkins · 23 Dec 2025
Company & tool watch

ThreatLocker, a zero-trust application whitelisting platform serving 70,000 companies, is worth watching as a representative of the default-deny endpoint control category increasingly adopted as a post-EDR layer.

“I have never had a customer with a ransomware case that wasn't ignoring obvious signs.”
Danny Jenkins · 23 Dec 2025
By the numbers

90 percent of ThreatLocker's customers start zero-trust deployment from a clean network, meaning proactive adoption drives uptake far more than incident response.

“For ninety percent of customers, they're starting from a clean slate.”
Danny Jenkins · 23 Dec 2025
By the numbers

70 to 80 percent of ThreatLocker support tickets are unrelated to ThreatLocker, as users misattribute pre-existing application issues to the zero-trust product.

“I would say seventy to eighty percent of our support tickets have nothing to do with us.”
Danny Jenkins · 23 Dec 2025
Worth quoting

Danny Jenkins on zero-trust onboarding speed, pushing back on the assumption that implementation takes months.

“I've onboarded people in hours.”
Danny Jenkins · 23 Dec 2025
Contrarian take

Zero-trust application whitelisting can be deployed in hours, not months, contradicting the widespread belief that such implementations require extended planning cycles.

“I've onboarded people in hours.”
Danny Jenkins · 23 Dec 2025
Signal Headquarters · reference note, compiled from attributed expert discussion. Last updated 2026-08-23.