The word 'sophisticated' gets thrown around a lot after a cyberattack. According to Danny Jenkins, CEO and Co-founder of ThreatLocker, that framing usually says more about the victim's desire to save face than it does about the attacker's capabilities.
In this conversation with CX Today, Jenkins makes the case that the vast majority of breaches trace back to the same handful of preventable mistakes: unprotected VPNs, untrusted software running freely, no multi-factor authentication. AI hasn't changed the fundamentals of how attacks work - it's just lowered the barrier to entry.
He said:
"It's just giving more people access to being a hacker. Whereas before you had to be relatively smart, a developer, now you can be anyone."
That democratization effect is showing up in the numbers. For every high-profile breach that makes the news, Jenkins estimates around 1,000 smaller companies are hit quietly.
Cybercrime operations run like businesses, with staff, quotas, and targets. Small companies get caught in blanket email campaigns of 20,000-plus recipients - targeted not because their data is particularly valuable, but because they can pay a ransom.



