Field Note Default deny, explainedFrom apprentice to founder70,000+ organizations protected$190M Series F in July 2026 Field Note Default deny, explainedFrom apprentice to founder70,000+ organizations protected$190M Series F in July 2026

Profile / Cybersecurity

Danny Jenkins Built a Security Company Around One Unfashionable Word: No

He left school for computers, learned to think like an attacker, and bet the grocery money on a simple defense: decide what is allowed, then refuse everything else.

The useful thing about a lock is not that it looks formidable. It is that, at the decisive moment, it says no. Danny Jenkins has built a career around making that small word do more work. His company, ThreatLocker, begins from a premise that sounds obvious only after someone has said it aloud: a computer should not run software merely because nobody has proved it dangerous yet.

Jenkins arrived at this doctrine by the untidy route. He grew up in the West Midlands of England, in an area he has described as rough. One student burned down his school. The rebuilt institution was called Phoenix, a name so literary that reality eventually corrected it: the school later closed amid crime problems. Jenkins left school at 15, started as an apprentice and landed his first professional IT job at 16. Security, as a recognizable industry, barely existed. Computers were the attraction. He liked taking them apart and rebuilding them.

That appetite became a working education. His career, which began in 1997, moved through corporate IT, network defense, ethical hacking and entrepreneurship. As an ethical hacker, he created malware and attack campaigns for clients, demonstrating how ordinary security controls could be bypassed. The job demanded an attacker's imagination and a repairman's patience. It also supplied a close view of the gap between being warned and being safe.

The recovery that could not recover

The turning point came during a ransomware incident. A client's business had been struck after a malicious email was opened. Jenkins worked at the recovery but eventually had to deliver the answer every consultant dreads: the files were gone. The attack disrupted operations and came close to destroying the company. There was no elegant forensic epiphany, only the bleak arithmetic of damage already done.

Cybersecurity had trained itself to recognize villains. Jenkins began wondering why unknown programs enjoyed the presumption of innocence. Detection asks whether a file or action resembles something malicious. His preferred model asks whether it has a reason to be there at all. It is less detective novel, more guest list.

In 2017, he founded ThreatLocker with Sami Jenkins, his wife, and John Carolan. Their first product centered on application allowlisting. Approved software ran; unapproved software did not. Ringfencing added another layer of restraint, limiting what an approved application could reach or do. A legitimate tool, after all, can still be abused. The idea was not to declare software morally pure. It was to give it a smaller room.

“We believe the better model is to define what is allowed and deny everything else by default.”Danny Jenkins, July 2026

Three cards at the checkout

The philosophy was strict. The finances were less orderly. Jenkins has said that he and Sami began ThreatLocker carrying about $150,000 in credit-card debt. At one point, an $80 grocery trip for a family of five had to be divided across three cards. Corporate origin stories acquire a soft glow in retrospect; supermarket payment terminals are less obliging. There were three children at home and no guarantee that a market would appear.

Jenkins describes the couple as “reckless enough” to see the company through. The line carries both a joke and an admission. Earlier ventures had neither become enormous successes nor collapsed into failures. This time, the wager was total enough to make caution feel luxurious.

One early argument concerned a trademark. An accelerator advised hiring a lawyer, an expense of roughly $5,000 when the business had less than $20,000 in the bank. The founders spent the money on sales and marketing instead. The advice proved correct: a later trademark dispute cost the company far more. But by then there were millions in the account. Jenkins's lesson was not that details do not matter. It was that a young company may die while protecting itself from the wrong future.

2017ThreatLocker incorporated and launched allowlisting
70,000+Organizations served, reported in 2025 and 2026
$190MSeries F announced in July 2026

ThreatLocker found its customers. It signed its first enterprise client in Florida in 2018, opened operations in Dublin, and broadened its platform into network, cloud, storage and privileged-access controls. By 2022 it had hired its hundredth employee and acquired Thirdwall and HyperCube. The company later opened offices in Dubai and Brisbane. By 2025, it said more than 70,000 organizations used its products.

Jenkins stayed close to the mechanics of selling and supporting the software. He has argued that growth did not require treating managed service providers as distant distributors. The company built direct relationships with them, listened to the people administering the product and kept support inside the proposition. It was a practical extension of the technical thesis: a restrictive policy is useful only if an IT team can manage it without turning every ordinary request into a small constitutional crisis.

That concern explains the platform's emphasis on learning what already runs in an organization before policies are enforced. Default deny can sound like a building in which every door is bricked shut. In practice, the aim is to inventory normal activity, approve the necessary pieces and leave a controlled process for exceptions. The distinction matters. Security imposed without regard for work becomes a tax; security designed around work can become infrastructure. Jenkins's commercial achievement has been persuading customers that the sterner rule need not produce the more irritating day.

Danny Jenkins speaking onstage at Zero Trust World
Onstage at Zero Trust World, Jenkins makes a severe security rule sound like household common sense: know what belongs before opening the door. Photo: ThreatLocker.

Growth, with the founder still attached

Rapid growth did not make Jenkins notably reverent toward conventional governance. When the board worried about a temporary dip, he kept accelerating market expansion. Founders still controlled the company, so directors could not simply stop him. His view of board authority is crisp: it should follow the number of hours someone works in the company, not the number of shares they own. Investors may wish to sit down before reading that sentence.

Yet the stance is not merely theatrical independence. Jenkins says he wants to finish what he started. Five years earlier, he might not have imagined remaining at ThreatLocker indefinitely; by 2025, he said he had no intention of leaving and discussed the possibility of an eventual public offering. The serial entrepreneur had become attached to the long middle of company building, where systems, support and hiring matter as much as invention.

Begins an IT and cybersecurity career spanning corporate networks, ethical hacking and incident response.

Co-founds ThreatLocker with Sami Jenkins and John Carolan.

Joins the Forbes Technology Council and is named among Orlando's influential business leaders.

Enters the Florida 500 as ThreatLocker reports more than 70,000 organizations served.

Raises a $190 million Series F for product development and further international expansion.

Recognition followed the scale. Jenkins received a Channel Futures Circle of Excellence award in 2023, appeared on the Orlando Business Journal's Most Influential Leaders list in 2024 and joined Florida Trend's Florida 500 in 2025. He became a member of the Forbes Technology Council, contributed commentary to business publications and hosted “Avoid the Hack” segments for Orlando television. He also backed no-cost cybersecurity education, including a Zero Trust bootcamp and events aimed at smaller businesses.

AI meets the problem of intention

The newest version of Jenkins's old argument concerns artificial intelligence. AI can help security teams analyze information, but he is skeptical of claims that it can reliably determine intent. An IT management tool and a hacker's remote-control tool may behave identically. Backup software and data-exfiltration software both move files. The action alone does not reveal the motive.

His answer is consistent: stop asking detection to perform philosophy. Limit the tool's reach. Decide which application may talk to which service, which files it may modify and which accounts it may use. This is why ThreatLocker's July 2026 funding announcement emphasized controls for AI agents alongside endpoint, network and cloud protection. The $190 million Series F, led by Elephant, was also earmarked for product development and international expansion, beginning with a new office in Reading, England.

For all the talk of agents and algorithms, Jenkins's personal tastes suggest a fondness for things that resist abstraction. He and Sami have repaved their driveway and backyard themselves after a storm. They are avid ice skaters. Both activities punish vague intentions. A paving stone is level or it is not; an edge either holds or sends you negotiating with gravity.

“I've always wanted to finish what I started.”Danny Jenkins

ThreatLocker's real product is control, but Jenkins's larger campaign is cultural. For decades, convenience won by default: install first, investigate later, and grant broad access because narrowing it was tedious. He is betting that better software can make restraint manageable. The ambition is not a world without malicious code. It is a world in which malicious code discovers, rather to its disappointment, that it has nowhere useful to go.

There is something bracingly unfashionable in this. Technology usually sells possibility. Jenkins sells boundaries. He learned from the business that could not recover, from the attacks he designed as an ethical hacker, and from a startup bank balance that allowed very few mistakes. A good system, in his telling, is not the one that recognizes every villain at the door. It is the one that already knows whom it invited.