As Cybersecurity Awareness Month kicks off, Danny Jenkins, CEO of ThreatLocker, says businesses should look beyond simply training employees to spot phishing emails and focus on building security controls that limit what an attacker can do when someone inevitably makes a mistake.
Danny has outlined five practical steps businesses can take to reduce their exposure:
1. Don’t let one bad click become a breach.
“We spend a lot of time telling employees not to click suspicious links, but the reality is that someone eventually will. Good security isn’t about expecting people to be perfect. It’s about putting controls in place so one mistake doesn’t give an attacker the keys to the entire organization.”
2. Make “default deny” the default.
“If an application or process doesn’t have a legitimate reason to run, why should it be allowed to run? A default-deny approach changes the equation from trying to identify everything that’s malicious to only allowing what the business has already decided it trusts.”
3. Give users and applications only the access they actually need.
“Least privilege is one of the simplest ways to limit the damage from a compromised account. If a user, application or service doesn’t need access to a particular resource to do its job, that access shouldn’t be there in the first place.”
4. Treat remote access as an attack path that needs to be controlled.
“Remote access is essential for modern businesses, but every remote connection is another potential path into the environment. Companies should be asking who can connect, what they can access, from which devices, and whether that access is still necessary.”
5. Reduce the attack surface before attackers find it.
“Security teams can’t protect what they don’t know they have. Unused applications, outdated software, unnecessary services and forgotten remote-access tools create opportunities for attackers. One of the most practical things a business can do is regularly remove what it no longer needs.”
Danny also recommends combining these technical controls with ongoing employee awareness training, strong identity security, network segmentation, software updates and monitoring. ThreatLocker’s Cybersecurity Awareness Month guide covers these and other practical measures for businesses and consumers.
Related
This entry was posted on October 2, 2026 at 3:27 pm and is filed under Commentary with tags ThreatLocker. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
ThreatLocker CEO on Cyber Awareness Month: 5 Ways Businesses Can Limit the Damage From One Bad Click
As Cybersecurity Awareness Month kicks off, Danny Jenkins, CEO of ThreatLocker, says businesses should look beyond simply training employees to spot phishing emails and focus on building security controls that limit what an attacker can do when someone inevitably makes a mistake.
Danny has outlined five practical steps businesses can take to reduce their exposure:
1. Don’t let one bad click become a breach.
“We spend a lot of time telling employees not to click suspicious links, but the reality is that someone eventually will. Good security isn’t about expecting people to be perfect. It’s about putting controls in place so one mistake doesn’t give an attacker the keys to the entire organization.”
2. Make “default deny” the default.
“If an application or process doesn’t have a legitimate reason to run, why should it be allowed to run? A default-deny approach changes the equation from trying to identify everything that’s malicious to only allowing what the business has already decided it trusts.”
3. Give users and applications only the access they actually need.
“Least privilege is one of the simplest ways to limit the damage from a compromised account. If a user, application or service doesn’t need access to a particular resource to do its job, that access shouldn’t be there in the first place.”
4. Treat remote access as an attack path that needs to be controlled.
“Remote access is essential for modern businesses, but every remote connection is another potential path into the environment. Companies should be asking who can connect, what they can access, from which devices, and whether that access is still necessary.”
5. Reduce the attack surface before attackers find it.
“Security teams can’t protect what they don’t know they have. Unused applications, outdated software, unnecessary services and forgotten remote-access tools create opportunities for attackers. One of the most practical things a business can do is regularly remove what it no longer needs.”
Danny also recommends combining these technical controls with ongoing employee awareness training, strong identity security, network segmentation, software updates and monitoring. ThreatLocker’s Cybersecurity Awareness Month guide covers these and other practical measures for businesses and consumers.
Share this:
Like this:
Related
This entry was posted on October 2, 2026 at 3:27 pm and is filed under Commentary with tags ThreatLocker. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.