704 ThreatLocker and Zero Trust: A Conversation with CEO Danny Jenkins
Aug 16, 2024
auto_awesome
Danny Jenkins, CEO of ThreatLocker, shares invaluable insights on zero-trust security and the importance of granting minimal privileges to enhance cyber defenses. He emphasizes a proactive management approach, detailing ThreatLocker's unified security bundle that includes allow listing and threat detection. The conversation touches on the challenges faced by Managed Service Providers in selling security solutions and the need for effective client communication. Jenkins also highlights their presence at Black Hat and the upcoming Zero Trust World event, showcasing the evolving landscape of cybersecurity.
ThreatLocker's zero-trust framework prioritizes the principle of least privilege, significantly reducing exposure to potential threats in cybersecurity.
Managed service providers must transition to proactive security management by educating clients and enhancing communication regarding security measures.
Deep dives
Importance of Changing IT Operations
Adopting a product like ThreatLocker can significantly change the way IT operations are managed. Initially, the transition requires a mindset shift among IT professionals, focusing on control and management rather than reactive problem-solving. A notable example from the podcast describes how implementing ThreatLocker allowed one family member to reduce their IT management time at a school from 30 hours a week to just one hour a month. This illustrates how effective tools can streamline operations and improve overall efficiency, ultimately leading to more manageable IT environments.
Understanding Zero Trust Security
Zero trust security is a critical concept in modern cybersecurity, emphasizing that access should only be granted based on necessity. The definition provided highlights that access should only be allowed to perform specific functions, thus limiting exposure to potential threats. ThreatLocker aids in achieving this by ensuring only authorized software can run, effectively preventing malware from executing on systems. This model further addresses network security by emphasizing that ports should only be opened to trusted devices, thereby enhancing overall network safety.
The Unified Security Bundle
ThreatLocker has introduced a unified security bundle that integrates several essential tools and services aimed at enhancing cybersecurity for businesses. This package includes allow listing, network controls, and a new endpoint detection and response (EDR) solution that addresses previous customer skepticism about existing tools. By combining these features into a single offering, organizations can reduce stack fatigue and might save costs while improving their security posture. Customers will benefit from integrated services like fast response times and thorough monitoring, all designed to mitigate risks effectively.
Evolving Roles for Managed Service Providers (MSPs)
As the landscape of cybersecurity shifts, the role of managed service providers (MSPs) is also changing to ensure thorough protection for client systems. The focus is now on proactive management rather than reactive fixes, highlighting the need for MSPs to educate clients about necessary security measures. Effective communication and documentation are equally crucial, as MSPs must ensure customers understand and accept their recommendations. By taking a decisive approach and providing clear guidelines, MSPs can create a secure environment for their clients while fostering trust and compliance.
Danny Jenkins provides insights into ThreatLocker's zero-trust framework and how it helps businesses implement the principle of least privilege. He explains the company's unified bundle, which combines allow listing, network controls, threat detection, and managed response services. Jenkins emphasizes the importance of shifting the security paradigm from default allow to default deny and educating the market about robust cybersecurity practices.
The conversation covers the challenges MSPs face in implementing and selling security solutions to clients. Jenkins stresses the need for clear communication, quick response times, and thorough documentation when dealing with security measures. He also discusses ThreatLocker's recent activities, including their presence at Black Hat in Las Vegas and their upcoming Zero Trust World event in Orlando.
Key Takeaways:
Zero-trust security is about granting the least amount of privilege necessary for a task
ThreatLocker offers a unified bundle combining allow-listing, EDR, MDR, and other security features
Zero Trust World is an annual cybersecurity event focused on hands-on learning and industry insights
MSPs need to evolve from IT support to proactive security management
The cybersecurity industry needs to catch up with cybercriminals, who are currently about two years ahead
AI-powered threats are increasing, creating new challenges for cybersecurity professionals
Clear communication with clients about security measures is crucial for MSPs
Zero Trust World 2025: FEB 19 - 21, 2025 at Caribe Royale, Orlando, Florida