Overview of SaaS Podcast with Danny Jenkins
In this episode, Omer Khan talks with Danny Jenkins, co-founder of ThreatLocker, about how he bootstrapped a cybersecurity company from a rough start—$150K in credit card debt, no customers for 18 months, and a failed accelerator experience—into a business approaching $200M in ARR and protecting 70,000 companies worldwide. The conversation focuses on the origin of ThreatLocker, why Danny doubled down on zero trust / application control, how he found product-market fit, and the mindset required to keep going when everything seems to be falling apart.
Danny Jenkins’ Background and Path into Cybersecurity
Early interest in computers
- Grew up in the UK, left school at 15, and didn’t complete formal exams.
- Taught himself through hands-on experimentation, including writing scripts and early malware-like tools.
- Got into IT by writing letters to every computer company in his town asking for an apprenticeship.
Career experiences that shaped the idea
- Moved into IT roles working on:
- computer assembly
- Novell network servers
- Small Business Server environments
- Later worked in Ireland for a large manufacturing company with global operations.
- Saw firsthand how a lack of security and centralized controls could turn a virus outbreak into a company-wide problem.
How ThreatLocker Started
The ransomware recovery that clarified the problem
- While running an email security business and consulting, Danny got pulled into a ransomware recovery in Australia in 2014.
- The attack had encrypted databases, Exchange, backups—everything.
- The customer ultimately asked: “Why didn’t our security tools stop this?”
- Danny realized the answer was to block by default and explicitly allow only approved software.
Why the product existed
- He also saw the same issue in his kids’ school IT environment:
- constant malware
- users running unauthorized software
- too much time spent firefighting
- ThreatLocker began as a way to make zero trust / application control practical for real-world businesses.
The turning point
- In 2017, WannaCry hit and ThreatLocker’s approach blocked it.
- Danny realized the opportunity wasn’t just a slice of the existing whitelisting market.
- Instead, he decided to create a new category by expanding the idea of zero trust to businesses of all sizes.
The Hardest Part: 18 Months With No Paying Customers
Building before selling
- In 2017, the team focused on getting the product to a usable MVP.
- The first “customer” was actually their own kids’ school.
Financial pressure
- The business ran on:
- depleted savings
- a remortgaged house
- credit cards
- Danny described being $150,000 in debt and buying groceries on multiple cards.
The accelerator mistake
- He joined an accelerator hoping for help with fundraising and growth.
- Instead, he says they mostly pushed him to pivot from whitelisting/zero trust to EDR.
- He felt the accelerator:
- wasted three months
- drained time and energy
- failed to deliver the promised investors or customers
Landing the First Customer
The first sale
- The first meaningful customer came in late 2018 after a trial and a very nervous sales call.
- Danny admits he was shaking when he asked for the close.
- The customer bought about $5,500 upfront for roughly 110 endpoints.
Why it mattered
- That first paying customer gave credibility.
- It helped unlock angel investment soon after.
- It proved the product could sell, not just function technically.
Go-to-Market: Sales, Trade Shows, and MSPs
What actually drove growth
- Early growth came from:
- cold calling
- demos
- webinars
- word of mouth
- customers sharing the product with peers
- Danny learned that sales is not magic—it’s about showing the product and asking for the order.
Sales lessons
- He initially hired a smooth-talking salesperson who didn’t close.
- A more blunt, direct salesperson later became far more effective.
- Key realization: don’t overcomplicate sales; keep it simple and direct.
Trade shows as a major growth engine
- In 2020, the company spent heavily on trade shows and speaking opportunities to educate the market.
- COVID shut that strategy down, but the pipeline had already been built.
- Revenue still scaled rapidly as awareness spread.
Why MSPs became important
- MSPs = Managed Service Providers, essentially outsourced IT teams for smaller businesses.
- MSPs gave ThreatLocker a way to reach many small businesses efficiently.
- ThreatLocker eventually saw massive growth through this channel.
Kaseya incident as a catalyst
- A major Kaseya vulnerability in 2021 led to ransomware being pushed through MSP infrastructure.
- ThreatLocker was positioned as one of the key tools that could block it.
- That event dramatically increased demand and awareness.
Core Product Philosophy
What ThreatLocker does
- ThreatLocker is built around zero trust application control:
- block by default
- explicitly approve what is allowed
- reduce ransomware and malware success
- Danny argues the challenge is not the concept—it’s making implementation easy enough for real organizations.
Why zero trust was controversial
- The security industry often sells detection products:
- antivirus
- EDR
- SOC
- threat hunting
- Danny believes many competitors downplay zero trust by calling it “too hard,” because it threatens their existing business models.
- ThreatLocker’s pitch is that zero trust is not impossible—it just needed to be made manageable.
Key Takeaways and Advice from Danny Jenkins
Startup advice he disagrees with
- Market research can be overrated.
- He believes the fastest way to validate an idea is to build it and try to sell it.
- Talking to 100 people is less reliable than asking a real buyer to pay.
Hard-won lessons
- Money doesn’t solve problems—it changes them.
- Early-stage problem: lack of cash
- Later-stage problem: hiring, scale, execution, and complexity
- Don’t get distracted by noise.
- When starting out, only two things matter:
- a product that solves a real problem
- customers knowing the product exists
- When starting out, only two things matter:
How he handles stress
- His mindset is very tactical:
- focus on what needs to be solved today
- don’t get overwhelmed by tomorrow
- deal with the most critical issue first
- He emphasizes urgency, proximity, and working closely with the team.
Personal Notes and Habits
Work style
- Danny says he works extremely long hours and keeps everyone physically close to solve problems faster.
- He prefers direct, in-person collaboration over long back-and-forths.
Outside work
- The main thing he and his wife consistently do outside of work is pair skating.
- It helps them disconnect and spend time together away from the business.
Notable Quotes and Ideas
- “The solution isn’t complicated. What’s complicated is the implementation.”
- “You need a product that solves a real problem, and you need the customers to know it exists.”
- “Money does not solve problems; it changes them.”
- “The fastest way to know if your product is viable is to get in front of someone and ask if they’ll pay for it.”
Final Outcome
What starts as a story of debt, rejection, and near-failure becomes a lesson in conviction and persistence. Danny Jenkins built ThreatLocker by:
- staying committed to a clear technical thesis,
- ignoring bad advice from people who didn’t understand the problem,
- using real customer feedback to refine the product,
- and turning a niche security approach into a large-scale cybersecurity platform.
