How Danny Jenkins Bootstrapped ThreatLocker From $150K Debt to $200M

Summary of How Danny Jenkins Bootstrapped ThreatLocker From $150K Debt to $200M

by Omer Khan

54m•July 2, 2026

Overview of SaaS Podcast with Danny Jenkins

In this episode, Omer Khan talks with Danny Jenkins, co-founder of ThreatLocker, about how he bootstrapped a cybersecurity company from a rough start—$150K in credit card debt, no customers for 18 months, and a failed accelerator experience—into a business approaching $200M in ARR and protecting 70,000 companies worldwide. The conversation focuses on the origin of ThreatLocker, why Danny doubled down on zero trust / application control, how he found product-market fit, and the mindset required to keep going when everything seems to be falling apart.

Danny Jenkins’ Background and Path into Cybersecurity

Early interest in computers

  • Grew up in the UK, left school at 15, and didn’t complete formal exams.
  • Taught himself through hands-on experimentation, including writing scripts and early malware-like tools.
  • Got into IT by writing letters to every computer company in his town asking for an apprenticeship.

Career experiences that shaped the idea

  • Moved into IT roles working on:
    • computer assembly
    • Novell network servers
    • Small Business Server environments
  • Later worked in Ireland for a large manufacturing company with global operations.
  • Saw firsthand how a lack of security and centralized controls could turn a virus outbreak into a company-wide problem.

How ThreatLocker Started

The ransomware recovery that clarified the problem

  • While running an email security business and consulting, Danny got pulled into a ransomware recovery in Australia in 2014.
  • The attack had encrypted databases, Exchange, backups—everything.
  • The customer ultimately asked: “Why didn’t our security tools stop this?”
  • Danny realized the answer was to block by default and explicitly allow only approved software.

Why the product existed

  • He also saw the same issue in his kids’ school IT environment:
    • constant malware
    • users running unauthorized software
    • too much time spent firefighting
  • ThreatLocker began as a way to make zero trust / application control practical for real-world businesses.

The turning point

  • In 2017, WannaCry hit and ThreatLocker’s approach blocked it.
  • Danny realized the opportunity wasn’t just a slice of the existing whitelisting market.
  • Instead, he decided to create a new category by expanding the idea of zero trust to businesses of all sizes.

The Hardest Part: 18 Months With No Paying Customers

Building before selling

  • In 2017, the team focused on getting the product to a usable MVP.
  • The first “customer” was actually their own kids’ school.

Financial pressure

  • The business ran on:
    • depleted savings
    • a remortgaged house
    • credit cards
  • Danny described being $150,000 in debt and buying groceries on multiple cards.

The accelerator mistake

  • He joined an accelerator hoping for help with fundraising and growth.
  • Instead, he says they mostly pushed him to pivot from whitelisting/zero trust to EDR.
  • He felt the accelerator:
    • wasted three months
    • drained time and energy
    • failed to deliver the promised investors or customers

Landing the First Customer

The first sale

  • The first meaningful customer came in late 2018 after a trial and a very nervous sales call.
  • Danny admits he was shaking when he asked for the close.
  • The customer bought about $5,500 upfront for roughly 110 endpoints.

Why it mattered

  • That first paying customer gave credibility.
  • It helped unlock angel investment soon after.
  • It proved the product could sell, not just function technically.

Go-to-Market: Sales, Trade Shows, and MSPs

What actually drove growth

  • Early growth came from:
    • cold calling
    • demos
    • webinars
    • word of mouth
    • customers sharing the product with peers
  • Danny learned that sales is not magic—it’s about showing the product and asking for the order.

Sales lessons

  • He initially hired a smooth-talking salesperson who didn’t close.
  • A more blunt, direct salesperson later became far more effective.
  • Key realization: don’t overcomplicate sales; keep it simple and direct.

Trade shows as a major growth engine

  • In 2020, the company spent heavily on trade shows and speaking opportunities to educate the market.
  • COVID shut that strategy down, but the pipeline had already been built.
  • Revenue still scaled rapidly as awareness spread.

Why MSPs became important

  • MSPs = Managed Service Providers, essentially outsourced IT teams for smaller businesses.
  • MSPs gave ThreatLocker a way to reach many small businesses efficiently.
  • ThreatLocker eventually saw massive growth through this channel.

Kaseya incident as a catalyst

  • A major Kaseya vulnerability in 2021 led to ransomware being pushed through MSP infrastructure.
  • ThreatLocker was positioned as one of the key tools that could block it.
  • That event dramatically increased demand and awareness.

Core Product Philosophy

What ThreatLocker does

  • ThreatLocker is built around zero trust application control:
    • block by default
    • explicitly approve what is allowed
    • reduce ransomware and malware success
  • Danny argues the challenge is not the concept—it’s making implementation easy enough for real organizations.

Why zero trust was controversial

  • The security industry often sells detection products:
    • antivirus
    • EDR
    • SOC
    • threat hunting
  • Danny believes many competitors downplay zero trust by calling it “too hard,” because it threatens their existing business models.
  • ThreatLocker’s pitch is that zero trust is not impossible—it just needed to be made manageable.

Key Takeaways and Advice from Danny Jenkins

Startup advice he disagrees with

  • Market research can be overrated.
  • He believes the fastest way to validate an idea is to build it and try to sell it.
  • Talking to 100 people is less reliable than asking a real buyer to pay.

Hard-won lessons

  • Money doesn’t solve problems—it changes them.
    • Early-stage problem: lack of cash
    • Later-stage problem: hiring, scale, execution, and complexity
  • Don’t get distracted by noise.
    • When starting out, only two things matter:
      1. a product that solves a real problem
      2. customers knowing the product exists

How he handles stress

  • His mindset is very tactical:
    • focus on what needs to be solved today
    • don’t get overwhelmed by tomorrow
    • deal with the most critical issue first
  • He emphasizes urgency, proximity, and working closely with the team.

Personal Notes and Habits

Work style

  • Danny says he works extremely long hours and keeps everyone physically close to solve problems faster.
  • He prefers direct, in-person collaboration over long back-and-forths.

Outside work

  • The main thing he and his wife consistently do outside of work is pair skating.
  • It helps them disconnect and spend time together away from the business.

Notable Quotes and Ideas

  • “The solution isn’t complicated. What’s complicated is the implementation.”
  • “You need a product that solves a real problem, and you need the customers to know it exists.”
  • “Money does not solve problems; it changes them.”
  • “The fastest way to know if your product is viable is to get in front of someone and ask if they’ll pay for it.”

Final Outcome

What starts as a story of debt, rejection, and near-failure becomes a lesson in conviction and persistence. Danny Jenkins built ThreatLocker by:

  • staying committed to a clear technical thesis,
  • ignoring bad advice from people who didn’t understand the problem,
  • using real customer feedback to refine the product,
  • and turning a niche security approach into a large-scale cybersecurity platform.