Cult Products podcast artwork for The Logic of Deny by Default: Building the Ultimate Security Guardrail

The Logic of Deny by Default: Building the Ultimate Security Guardrail

Phill Keaney-BollandPhill Keaney-Bolland· Co-founder and Designer, Yaya2 min read

With Rob Allen, Chief Product Officer, ThreatLocker

Key takeaways

  • Deny by default stops unknown malware in a way that trust but verify structurally cannot.
  • Double extortion ransomware changed what recovery means, because backups stopped being enough.
  • AI is useful for categorization and unfit for the final allow or deny decision.
  • Ringfencing is what makes adopting agentic AI survivable.
  • Highly trained security engineers still fall for AI-crafted phishing.

Two decades of cleaning up#

Rob’s argument carries weight because of where he formed it. Nearly twenty years at a managed service provider in Ireland, dealing with the consequences of a model that permits anything not yet known to be bad. The turning point was watching a double extortion attack, where exfiltration alongside encryption meant that having good backups no longer meant having a recovery.

Why deny by default is structural#

The distinction Rob draws is not about product quality but about logic. A model that blocks what it recognizes as malicious will always trail the people producing new malicious things. A model that permits only what has been approved does not have that lag, which is what neutralizes zero-day threats and unknown malware.

The 15 percent problem#

Rob is measured rather than dismissive about AI in security. Categorization is a good fit. Final allow or deny decisions are not, and the reason is arithmetic: an error rate that would be acceptable in most applications is catastrophic when the decision is whether to let something execute across an estate.

It is a more useful position than either AI maximalism or refusal, and it maps onto the guardrail argument we hear repeatedly. An agent will reach further than it should if nobody is watching.

Ringfencing and agentic AI#

Ringfencing limits what an approved application is allowed to do once running. Rob makes the case that this is what allows organizations to adopt agentic AI without accepting unbounded blast radius, and covers Zero Trust Network Access as the route to closing exposed ports.

The culture underneath the growth#

A lighter but genuinely useful thread covers how ThreatLocker operates internally: a 60 second support response target with an alarm attached, and random pitch-offs that require every employee to be able to explain the mission.

Phill Keaney-Bolland

Phill Keaney-Bolland

Co-founder and Designer, Yaya

Co-founder and designer at Yaya, and host of the Cult Products podcast. Fifteen years designing products, brands and UX across multiple industries before narrowing to cybersecurity, and lectures on design at Imperial. Works with cybersecurity founders on positioning, strategy and the website that has to carry a launch, across identity, cloud security, AI agents and software supply chain, including Twine out of stealth and Geordie AI, which won the RSA Innovation Sandbox in 2026.

Frequently asked questions