

Misconfiguration, The Forgotten Vulnerability and the Power and Failure of "Yes" - Danny Jenkins - BSW #409
14 snips Aug 20, 2025
Danny Jenkins, CEO and co-founder of ThreatLocker, dives into the often-overlooked vulnerabilities of misconfigurations in cybersecurity. He emphasizes how these can lead to significant security breaches and discusses ThreatLocker’s innovative Defense Against Configurations (DAC) feature, which provides real-time visibility into system misconfigurations. The conversation also highlights the importance of proactive engagement in security settings and explores how data-driven recommendations can enhance security measures. Jenkins advocates for governance in tech leadership and stresses the need for effective communication to mitigate risks.
AI Snips
Chapters
Transcript
Episode notes
Misconfigurations Drive Real-World Breaches
- Misconfigurations, not missing tech, often enable attacks because controls are turned off or set wrong.
- ThreatLocker found MDR teams acting as "configuration police" fixing human errors that cause breaches.
Monthly Configuration Service Always Finds Issues
- Adrian ran a consulting service that checked security tool configurations monthly and always found misconfigurations.
- Tools were often installed but left without policies or final steps completed.
Run Daily Configuration Checks
- Run automated daily configuration checks across devices to surface misconfigurations before attackers do.
- Report counts by criticality and deliver actionable remediation steps so teams can fix issues quickly.