ThreatLocker Raises $190 Million to Expand Its Block-Everything-First Security Model
The Florida firm now counts more than 70,000 business customers and is opening a UK office on the back of its latest funding haul.

Key points
- ThreatLocker raised $190 million in a Series F funding round, announced Wednesday.
- The round was led by investment firm Elephant, with backing from D. E. Shaw Ventures, Arthur Ventures and Koch Disruptive Technologies.
- A source familiar with the deal told SecurityWeek that ThreatLocker was valued at $1.6 billion in its previous round; the new raise pushed that figure higher.
- ThreatLocker says its software is used by more than 70,000 organisations worldwide.
- New money goes toward product development and a UK office, following recent expansions into Australia and the UAE.
What does ThreatLocker actually do?
ThreatLocker sells endpoint security software. An endpoint is any device on a company's network: a laptop, a server, a point-of-sale terminal.
The company's pitch is built on zero trust, which in plain terms means the software blocks every programme from running unless a company has explicitly approved it. Think of it as a strict nightclub bouncer working from a whitelist: if your name isn't on the list, you don't get in.
That matters because most security tools work the other way around. They try to spot known bad software and block it. The failure mode is obvious: attackers write new malware the scanner hasn't seen before.
ThreatLocker's platform also restricts what approved apps can do once they're running, limits storage access and manages user privileges. It filters network traffic by application identity rather than just by port or address, monitors for indicators of compromise (behavioural signs that a device is acting strangely) and can respond automatically.
Why does a funding round matter to ordinary people?
On its own, a fundraise doesn't affect anyone who doesn't own shares. In practice, though, where security money flows tells you which problems the industry thinks are still unsolved.
The $190 million bet here is that blocking software by default beats chasing malware after it lands. If that approach scales, the downstream effect could be fewer ransomware attacks, where malicious software locks a business's files until a ransom is paid, hitting schools and hospitals alike.
Each round has funded broader reach: Australia and the UAE in the past 18 months, and now the UK.
Should small businesses or IT teams pay attention?
Yes, especially if you manage devices without a large security team. The zero trust model ThreatLocker is selling means less reliance on analysts manually hunting threats, because the default stance is denial.
One thing the post-mortem says after many breaches is that an attacker ran a programme no employee should ever have needed. A deny-by-default policy would've stopped that cold. As we noted covering Glow's $180 million raise on 22 July, the default-deny camp is attracting serious capital right now.
If your security stack is still built entirely around detection, you're betting that every piece of malicious code will be one your tools have already seen. That's a bet worth revisiting.



