Stopping Cyberattacks before they Start
Most cyberattacks now begin with stolen credentials. Could Zero Trust stop them before they start? Phishing, credential theft and ransomware now dominate the cyber threat landscape. Instead of breaking into systems directly, attackers increasingly gain access by stealing credentials and logging in as legitimate users.
Cybersecurity company ThreatLocker believes the most effective defence is to stop unauthorised activity before it can run.
During Zero Trust World 2026, the company's annual cybersecurity conference in Orlando, I interviewed ThreatLocker CEO and co-founder Danny Jenkins about how the company is responding to this shift in cyber threats.
Jenkins described the company's philosophy in simple terms.
"Our goal has always been to stop attacks before they start," he told me. "If something isn't explicitly trusted, it simply shouldn't be allowed to run."
That principle underpins ThreatLocker's deny-by-default Zero Trust platform, which allows only approved software and activity to operate inside an organisation's systems.
The latest expansion of the platform focuses on one of the fastest-growing threats facing businesses today: credential-based cyberattacks.
ThreatLocker Targets Credential-Based Cyberattacks
A central announcement at the conference was the extension of ThreatLocker's Zero Trust controls to corporate networks and cloud services.
Jenkins explained that the new capability verifies three elements before granting access: valid credentials, an approved device and a secure connection brokered through the ThreatLocker platform.
"Our transformative solution gives organizations confidence that their systems are secure even if a credential is stolen," he explained during our discussion.
If any one of those elements is missing, access is denied.
The approach is designed to stop attackers even if a user has been successfully phished.
Why Credential Theft has become a Major Security Risk
Much of our conversation focused on how cyberattacks have evolved.
Credentials are the digital keys that allow users to access systems. They usually include usernames, passwords and authentication tokens that confirm a user has logged in successfully. If attackers obtain those credentials, they may be able to access systems while appearing to be legitimate users.
Jenkins noted that authentication tokens have become a growing vulnerability.
"In many cases attackers don't even need your username and password anymore," he told me.
He explained how attackers can capture login tokens issued after a successful authentication.
"Once someone logs in, a token is issued to the device. If an attacker captures that token they can potentially access services without ever using the original credentials."
Artificial intelligence is also accelerating the problem. When I asked about the future of cyber threats, Jenkins pointed out how AI tools have lowered the barrier for generating malicious software.
"Twenty years ago there were probably a relatively small number of people capable of writing sophisticated malware," he said. "Today someone with no development experience can go to an AI system and generate malicious code in seconds."
For Jenkins, these developments reinforce the need for security models focused on prevention rather than detection.
"If something isn't explicitly trusted, it simply shouldn't be allowed to run."
Extending Zero Trust Protection to Networks and Cloud Services
The capability introduced at Zero Trust World extends ThreatLocker's existing controls to corporate networks and cloud platforms.
In practice this means that even if a user is successfully phished, attackers cannot access company systems unless they also possess the trusted device associated with the account.
ThreatLocker says the platform can protect access to widely used services including Microsoft 365, Salesforce, Google Workspace, GitHub and Asana.
By verifying both the user and the device making the request, the system ...