The Blog
Perspectives on Zero Trust, MDR, and managed cybersecurity from the team defending it every day. No fluff, no vendor pitch, just what we’re seeing in the field.
Stay up to date
Get the latest news, publications, threat research and Zero Trust guidance from ON2IT, straight to your inbox. No spam, unsubscribe anytime.
Latest blogs
3 Things Your Firewall Already Blocks in GenAI Traffic
If you already run a Palo Alto Networks firewall, you already hold an AI control point. The decision in front of you is not whether to deploy something new. It is how far up the stack you want to turn capability on.
Your security culture will fail. That's not the problem
AI-driven attacks now run faster than human analysts can respond. Here is what closing the speed gap actually requires, and why buying tools is not the same as building defense.
What every CEO asks their CISO before vacation. Because while you're gone, Mythos, Kimi or others will land.
Five questions every CEO should ask their CISO before vacation, with evidence, not assumption, on exposure, patch speed, breach detection, privileged access, and blast-radius containment.
Your Security Culture Will Fail. That's Not the Problem.
Security culture fails under pressure. Learn why culture programs are the wrong fix and how Zero Trust architecture contains the damage when culture breaks down. Secondary keywords: Zero Trust security culture, security culture failure, Protect Surface, hero culture cybersecurity, risk exemption, NIS2 accountability, CISO security architecture, prevention paradox, MDR Prevent, MDR Detect
Everyone in Your Organization Thinks Someone Else Is Handling Cyber Risk
60% of executives rank cyber risk as a top priority. Only 6% have the controls to match. Here is what closes the gap, and the four conditions ON2IT sees in the organizations that have.
AI just found the bugs. We just patched yours.
Palo Alto Networks, one of the most respected security engineering teams on the planet, pointed an AI agent at their own source code.
One Implementation. Multiple Frameworks.
Most organisations run their Zero Trust programme and compliance programme as two separate workstreams. A properly structured Zero Trust implementation produces compliance evidence as a natural output — satisfying ISO 27001, NIST, SWIFT CSP, DNB, PCI DSS, NIS2, and DORA simultaneously.
Agentic AI Is Now a Breach Vector. Zero Trust Was Built for Exactly This.
Agentic AI is now a breach vector. Zero Trust governs actors with legitimate credentials, and applies to AI agents without modification. Five actions CISOs should take now.
You don't need additional AI security tooling | ON2IT Blog
AI vendors are pitching a new generation of security tools. Most organizations don't need them. They need to execute Zero Trust on the stack they already own.
Critical infrastructure cyber legislation is changing who you can buy from
Europe and the US are rewriting the rules on who can supply your critical infrastructure. Here's what the new cyber legislation means for your vendors, your budget, and your deadlines – and what to do before the window closes.
You can't outrun bad infrastructure | ON2IT Blog
Cortex XDR and Zero Trust work better together. See why your detection capability is only as strong as the infrastructure it runs on.
Zero Trust for AI Agents
AI agents expand the attack surface. Learn how Zero Trust for AI agents strengthens agentic AI security and protects non-human identities in modern enterprises.
MDR vs XDR – why the difference costs you time
MDR gives you coverage. XDR gives you clarity. Most organizations need both. Here's how to tell which problem you're actually trying to solve.
Why Your SOC Is Drowning. And What XDR Changes (and Doesn't)
Security teams have invested in SIEM, SOAR, and XDR, yet many SOCs remain overwhelmed. XDR helps, but doesn't automatically fix operations. Learn what actually matters.
Five Real Challenges to Zero Trust Implementation
Zero Trust implementation fails when access control isn't enforced. Learn the real blockers and how to operationalize Zero Trust effectively.
The EU Cybersecurity Act Redefines Vendor Risk
Vendor risk is evolving under the EU Cybersecurity Act. Learn how supply chain security is becoming regulatory exposure for CISOs and CIOs.
The Modern SOC Was Not Built for AI-Speed Threats
Attackers operate at machine speed with AI tooling. Traditional SOC teams struggle to keep pace. Learn how to operationalize detection and response that actually matches threat speed.
Why Hospital Cybersecurity Fails on Paper (and in Practice)
Hospital cybersecurity can look compliant while remaining operationally fragile. Learn why audits miss OT blind spots, vendor lock-in, and availability-driven risk.
A Practical Guide to Cryptographic Agility Before Q-Day
Post-quantum cryptography is already underway. Build cryptographic agility now to replace algorithms without operational disruption when quantum threats arrive.
MDR vs EDR vs XDR - Making Sense of Cybersecurity's Acronym Soup
EDR, XDR, and MDR are not interchangeable. One is a tool. One is a service. One is an outcome. Learn which fits your security operations.
OT needs Zero Trust 2.0
The IT/OT convergence flips the script on security. Traditional models such as the Purdue Model were designed for separation. Today’s reality demands something different: a model that ditches static boundaries and kills implicit trust. That’s where Zero Trust 2.0 for OT security comes in.
Cybersecurity awareness in 2026 meets NIS2
Cybersecurity awareness in 2026 goes beyond training. See how CISOs should address AI risk, NIS2 compliance, and supply chain threats.
Modern MDR: Threat Detection That Starts at Ingestion
Sub-second detection reduces attacker dwell time by analyzing threats at log ingestion. Learn how real-time detection stops lateral movement and operational risk before it’s too late.
The Norwegian Dam Cyberattack: OT Security Wake-Up Call
By examining the Lake Risevatnet incident through the lens of the SANS Five ICS Critical Controls, it becomes clear how established safeguards could have reduced both the likelihood of the intrusion and its operational impact.
In Cybersecurity, Choosing to Stay Is the Signal
Long-tenured cybersecurity experts matter. ON2IT celebrates teammates who choose to stay and strengthen our Zero Trust SOC with experience, trust and continuity.
Cybersecurity Predictions for 2026: From Reaction to Prevention
In 2026, prevention overtakes reaction as AI-driven threats scale. Explore the key cybersecurity predictions shaping Zero Trust, exposure reduction, and resilience.
Cybersecurity in 2025: AI Attacks, Ransomware at Scale, and Board-Level Risk
In 2025, cybersecurity changed fast. AI-driven attacks scaled, ransomware industrialized, and regulation made cyber risk a board-level issue. Here’s what changed - and what leaders must do before 2026.
The Future of Cyber Insurance: From Reactive Reimbursement to Risk-Based Resilience
Cyber insurance is shifting to real-time risk measurement. Zero Trust, telemetry, and maturity scoring define Cyber Insurance 3.0.
The risk of rushing into post-quantum cryptography: the ballad of FOMO, YOLO and FAFO
Get solid control over your configurations. Bake agility requirements into procurement and development. Streamline your change process so swapping cryptography does not feel like open heart surgery.
The hidden tax of data lakes: when detection becomes a storage problem
This post breaks down why traditional data lake–centric detection pipelines create hidden costs, retention creep, sovereignty exposure-and why modern MDR models like MDR Detect™ eliminate the entire category of “storage tax” by keeping your logs in your cloud.
Threat Talks Revisited: What We Got Right (and Wrong) About 2025
When we kicked off 2025, we put a few bold predictions on the table. Not the vague kind. The kind that shaped every conversation we had on the podcast: AI would get real, Zero Trust would spill into supply chains, the skills gap would stretch even further, regulation would hit the brakes, and AI’s power use would stop being a footnote and start being a problem.
Your Logs, Their Cloud: Why Data Ownership Defines Modern Detection & Response
Discover why modern MDR must keep your logs in your cloud. Learn how data sovereignty, cloud waste, and vendor data lakes impact cost, control, and detection.
The Internet of Weapons: How Everyday Devices Power Global Botnets
Billions of everyday connected devices – routers, cameras, and even smart home gadgets – are being hijacked into massive IoT botnets.
How Zero Trust Is Transforming Cyber Insurance in Financial Services
Zero Trust is changing how insurers price cyber risk - see how financial leaders are turning security maturity into lower premiums.
Beyond the Hype: Why AI SOC Agents Need Managed Expertise to Deliver Real Value
AI is transforming SOC operations - but not replacing them. Learn why managed expertise is key to turning AI agents into measurable, trusted outcomes.
The Standard We Set: Trust, Power, and the Quiet Politics of Cryptographic Standards
Cryptographic standards define digital trust, but they also reflect policy, power, and risk. Learn how transparency and agility create verifiable trust.
Resilience by Design: Future-Proofing Security with MDR Detect™
Resilience is the new measure of cybersecurity. Discover how ON2IT’s MDR Detect™ turns detection into recovery — fast, smart, and built to last.
New Texas agency will create a Lone Star shield for cyber defense
Texas has a reputation for thinking big and acting decisively. With the signing of HB 150 in June 2025, Gov. Greg Abbott and the Texas Legislature created the Texas Cyber Command, positioning Texas as a national leader in cybersecurity.
When Machines Detect, Humans Decide
In the AI race, speed is the goal. Security is the collateral. When a real attack lands, machines can detect. Only humans can decide what happens next.
When cybersecurity equals national security
Summary Hybrid warfare isn’t theory anymore. It’s reality. In the Nordics, GPS jamming, drone fly-bys, and fake-news blitzes are testing how nations hold their
The Forgotten Protect Surface: Securing SaaS in a Zero Trust World
Cut through the noise and find out how to turn SaaS from a soft target into a secured stronghold: from shared responsibility to access control, network segmentation, and data in motion.
The End of Alert Fatigue: Clarity Is the New Speed
Alert fatigue has quietly become one of cybersecurity’s biggest risks. It drains focus, wastes time, and erodes trust in the very systems meant to protect us.
CISO’s Practical Guide to XDR: What to Do Now - And When to Add Extended Detection and Response (XDR)
This is a hands‑on guide on what to do now - and when to add extended detection and response (XDR).
Cybersecurity and the so-called 'weakest link'
While people make mistakes, they also adapt, think on their feet, and save the day when systems fall short. We’re not the weakest link in cybersecurity. We’re the most resilient one.
How a single breach froze Jaguar’s global network
One breach. Four continents. Zero production. At the end of August 2025, Jaguar Land Rover’s smart factories went silent after attackers slipped through unchecked access and spread fast.
From Noise to Clarity: SIEM vs XDR and the Turning Point in Cybersecurity Analytics
For years, SIEMs formed the backbone of security operations. But the threat landscape has changed. The same systems that once gave control now create noise.
Hack the Hospital: Cybersecurity requires Critical Care
When an attacker takes control of hospital systems, it’s not a spreadsheet that breaks. It’s the oxygen supply, the water treatment system, the temperature control in the ICU. A single digital command can ripple into the realy world: quietly, instantly, dangerously.
Fog of War: See First, Win First
Generals call it the fog of war: the chaos, the half-truths, the missing signals that twist decisions. Cybersecurity faces the same fog: you can’t defend what you can’t see.To understand why visibility decides outcomes, look no further than where the idea began – the battlefields of the past.
Understanding PQC Algorithms
Quantum computers could break today’s cryptography. Discover five PQC approaches, NIST standards, and how agility keeps cybersecurity future-proof.
10 insights from banking CISOs on smarter cybersecurity investments
Discover 10 key insights from U.S. banking CISOs on cutting tool sprawl, SOC costs, and compliance fatigue. Learn how Zero Trust can reduce breach costs by up to 75%.
Zero Trust isn't "hard" - it's unfocused.
Zero Trust isn’t hard – it’s about focus. Most CISOs struggle because they treat Zero Trust like an all-or-nothing moonshot. In reality, Zero Trust is a strategy applied incrementally to one protect surface at a time, using tools organizations already own.
Zero Trust security: what it is and why it matters
A comprehensive guide that explains Zero Trust, a cybersecurity strategy built on the principle of "never trust, always verify".
OT Security: Lessons from a train hack
A newly confirmed vulnerability in train braking systems has resurfaced after more than two decades, and it’s finally getting some traction. In short, this vulnerability allows attackers to send unauthenticated radio signals that can trigger emergency brakes, putting public safety at risk.
From perimeter defense to precision-driven: a shift in war and cybersecurity strategy
For decades, scale defined strength. In both military doctrine and cybersecurity, the default mindset was straightforward: the bigger the wall, the better the protection.
OT Cybersecurity 101: An Essential Guide for Security Teams
Operational Technology (OT) refers to the hardware and software that control physical systems like factory equipment, power grids, or hospital machines. Unlike IT, which focuses on data access and user services, OT is about delivering physical products and tangible services.
Harvest Now, Decrypt later: preparing for quantum computing threats
Attackers exploit current cryptographic vulnerabilities. Malicious actors intercept encrypted communications, store them indefinitely, and wait patiently for quantum advancements to render encryption obsolete. This might raise a natural question: why would someone care about decrypting data a decade from now?
Cybersecurity starts with people
Working in security at a cybersecurity company demands a specific mindset. Frameworks, compliance standards, regulations, and tooling all have their place, but they’re not where we begin.
Cryptographic Agility: Designing for Change, Planning for Failure
Indecision is the basis of flexibility. WHAT IS CRYPTOGRAPHIC AGILITY? Cryptographic agility is the principle of designing systems in a way that allows
Rethinking Log Management
Imagine standing in the British Library. Millions of books, no organization, no labeling—just shelves overflowing with unsorted information. Somewhere in that chaos is a clue to stop a thief, and it’s your job to find it. That’s what modern cybersecurity teams face every day.
What are we doing here? Cryptography pre-and post-quantum
And when you look along the way we’ve come, there are spirals of vultures wheeling. — Bruce Chatwin, The Songlines (2012) THE NEED FOR SECURITY Sometimes we need a
Is our definition of 'an act of war' outdated?
When we think of war, most of us picture something loud and visible. Tanks rolling through fields, soldiers in uniform, fighter jets in the sky. It’s an image
Cybersecurity for AI: How to protect AI systems you use or own
An employee asks if they can deploy their own AI agent to process internal documents. They’ve found one that runs effortlessly via a cloud service and “just needs
Zero Trust from conviction, not fear
Security isn’t about locking doors after intruders have come and gone. It’s about designing a world where they never get in. Imagine waking up to find someone’s
Signed, Sealed, Subverted: What Broken Cryptography Teaches Us About Trust
The Trusted Signature You’re alone in a quiet gallery of the Rijksmuseum, the soft hum of security systems barely audible beneath the air conditioning. A dim
How Zero Trust is Reshaping Cyber Insurance
On May 23rd, 2025, stakeholders from various large insurers met in New York City to dicsuss how cyber insurance is evolving, and how Zero Trust is increasingly at the center of the major cyber insurance shift.
ON2IT's Global CISO Dr. Yuri Bobbert Honored with ISACA Inspirational Leadership Award
ON2IT proud to announce that Dr. Yuri Bobbert, the company's Global Chief Information Security Officer, has received the prestigious ISACA Inspirational Leadership Award.
Behind the Scenes of Cybersecurity Assessments: An Interview with Tim Timmermans
A comprehensive cybersecurity assessment is a proven method to achieve insight and overview. But how exactly does such an assessment work, and why is it vital to safeguarding your business?
ON2IT Launches AUXO Curator™, Enhancing ON2IT MDR Services
ON2IT, the pioneer in Zero Trust as a Service (ZTaaS), today announced AUXO Curator™, a major enhancement to its Managed Detection & Response (MDR) service that enables seamless ingestion of security log data from any source—across IT, OT, and cloud environments.
International Adoption of Zero Trust
As global cyber threats increase and new technologies emerge, the adoption of the Zero Trust (ZT) security strategy is gaining traction across borders and industries.
Zero Trust in Action: Lessons from the Shipyard
ON2IT Zero Trust implementation case study for the CSA ZT workgroup about protecting critical infrastructure in a European Shipyard.
Purdue vs Zero Trust in OT security
The Purdue Model has long served as a foundation for securing OT environments, but its limitations in addressing modern cyber threats are evident. Zero Trust enhances OT security by enforcing strict access controls, continuous monitoring, and micro-segmentation.
How Zero Trust can strengthen cybersecurity for U.S. community banks
Community banks play a vital role in local economies, yet they face increasing cybersecurity challenges. Unlike larger financial institutions, they often struggle with limited resources, outdated technology, and complex regulations.
Trust people, not packets
Let’s clear something up right away: Zero Trust does not mean we don’t trust people. It means we don’t blindly trust the digital traffic moving through our networks. And yes, that distinction matters, a lot.
CISO responsibilities: Too much to handle?
Once a primarily technical position, the role of Chief Information Security Officer (CISO) now comes with a range of new responsibilities. Executives increasingly rely on CISOs; but this can be risky.
ON2IT Joins Texas DIR Cybersecurity Contract
ON2IT, a global leader in Managed Detection and Response (MDR) and Zero Trust cybersecurity, is proud to announce its inclusion in the Texas Department of Information Resources (DIR) Cybersecurity contract (DIR-CPO-4843).
Cybersecurity predictions for 2025: AI, quantum computing and compliance
The rapid technological advancements of the past few years (or decades, depending on how far back you want to scroll) are only picking up speed, and the threats we face will keep evolving just as fast. But what does that actually mean for 2025?
Zero Trust: A New Year’s resolution worth keeping
As the year draws to a close, it’s time to reflect on the past 12 months and make plans for the year ahead. For those of us in cybersecurity, the question is clear: what did we do to strengthen our security posture this year, and how can we do even better next year?
ON2IT creates holistic approach to security & regulatory compliance
ON2IT, a global pure-play cybersecurity service provider in the Netherlands, developed a solution to measure and improve their cybersecurity posture while strengthening their compliance with several local and European regulations.
Bridging the gap: Security & Compliance
Some CISOs fear auditors more than they fear actual hackers… Compliance has become a crucial focus with the implementation of regulations like the GDPR, CCPA, and various global data privacy directives. But whilst many organizations have rightfully turned their focus to said compliance, does it actually ensure better (cyber)security?
The secret sauce for boardroom trust
We challenge you to look at cybersecurity assessments through a different lens. IT and executive leaders alike should recognize assessments for the sanity check they are, as well as a way to build trust within the organization. Not as some sort of score card or grading system, but as a way to figure out where to start and where to go next.
Hack the Boat
Though the recent Baltimore bridge collision wasn’t a cyber-attack, it did showcase a serious vulnerability in ship systems. A vulnerablity that could’ve easily been exploited by hackers, highlighting a truth that can no longer be denied – ships are easy targets for cybercriminals.
Cyber warfare
In these cyber warfare episodes of Threat Talks, we explore whether or not we stand a chance in this continuous arms race in cyber technologies, what Advanced Persistent Threats (APTs) are, and how these modern threats can affect literally everyone.
The cybersecurity paradox
PwC’s Dutch CEO Survey shows that 56% of Dutch CEOs are very concerned about cyber risks. The Allianz Risk Barometer lists cyber incidents as the biggest worry for companies globally and Gartner’s 2023 Top Cybersecurity Trends reports that business leaders are recognizing cybersecurity as a top business risk, yet organizations still struggle with implementing the necessary measures to mitigate risks.
How to face the ‘ever-evolving cyber threat landscape’
If you’ve read any cybersecurity articles lately, you’ve likely come across the term ‘ever-evolving cyber threat landscape.’ It’s one of those phrases that gets thrown around a lot – especially in AI generated content – almost to the point of sounding cliché. But here's the truth: as cliché as it may sound, it's not just a buzzword.
Why a cybersecurity assessment is not a vote of no confidence
Even if you’re an IT professional feeling a bit skeptical about the board’s intentions, you can still see that their involvement is a great chance to align security measures with the company’s broader goals. It’s all about framing this as a partnership, not a critique. One of the best ways to do that is through a cybersecurity assessment that actually makes sense.
Breaking the bank
How do you stop these modern bankrobbers from targeting your financial institution? In this Breaking the Bank episode of our Threat Talks podcast, our special guest and renowned cybersecurity expert Jayson E. Street shares his experiences on how he ethically “robs” banks to reveal security weaknesses.
The crucial role of business alignment in cybersecurity
Though Zero Trust is here to stay, that doesn’t mean implementation is easy. Rob Maas is one of the leading Zero Trust consultants and the Field CTO at ON2IT. In this second part of his blog series he answers the question: what part does business alignment play in cybersecurity implementations?
Healthcare: Responsibilities, regulations and legacies
Cyberattacks on healthcare organizations can put patients’ lives and entire organizations at risk. There are numerous reasons why cyber attackers seem to favour healthcare facilities as a target: private patient information is worth a lot of money, medical devices are easy entry points, and there’s a lot of outdated technology.
Resilience in the face of adversity
There was a time when today’s tech-giant Apple faced bankruptcy. What happened, and how did Apple get to where it is now despite facing adversity?
The Authentication Apocalypse
Join us on the latest episode of Threat Talks, aptly named 'Authentication Apocalypse.' Our hosts, Lieuwe Jan Koning and Luca Cipriano, explore the pressing topic of authentication with Harald Bosman, a seasoned endpoint engineer from AMS-IX.
Supply chain - Business as usual?
In this ‘Suppy chain – Business as usual?’ episode of Threat Talks, Lieuwe Jan Koning and Luca Cipriano dive into the escalating risk of supply chain attacks amid growing reliance on third-party and open-source software. Featuring insights from Matthijs Zwart, CIO and CISO of Vitens, the discussion explores the implications of these threats in critical sectors like water supply.
False sense of cybersecurity
Adopting a transformative cybersecurity strategy can redefine business success. While the current adoption rate or Zero Trust – a transformative cybersecurity strategy – among large enterprises is just 1% as of January 2023, Gartner projects a growth to 10% by 2026.
Can't deny DDoS in 2024?
DDoS attacks are orchestrated efforts where malicious actors aim to disrupt the normal flow of traffic to a specific server, service, or entire network. They flood the target with a torrent of internet traffic—much like those empty boxes in our scenario—making it impossible for legitimate traffic to get through. These attacks can cripple websites, slow down services, or even bring them to a complete halt, affecting businesses and users alike.
Optimism bias won’t save you
With cybersecurity still a hot topic, news alerts about the latest data breach or security incident are hard to miss. Yet, even whilst being bombarded with these types of news items, many companies still think that they’re somehow immune to such threats. This optimism bias tends to come in three different flavors.
VPN-Firewall Integration: A Strategic Analysis
Integrating various network functions within a single device, such as combining VPN (Virtual Private Network) capabilities with firewalls, has become a common practice over the past few years. This consolidation offers benefits in terms of platform security features (i.e. user-based policies and Layer 7 inspection), simplicity and cost-effectiveness.
Decoding the attack: Forensic tips for understanding CVE-2024-3400 exploits
Let’s shed some light on this new vulnerability published by Palo Alto Networks. First off, what exactly is CVE-2024-3400? It’s a vulnerability in the GlobalProtect feature of Palo Alto Networks’ PAN-OS software, with the highest severity score of 10.
CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect
Palo Alto Networks published vulnerability CVE-2024-3400 that allows unauthenticated command injection (RCE) in the GlobalProtect feature of Palo Alto Networks PAN-OS software. Specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.
Navigate the challenges of remote work
For enterprises large and small, remote access is no longer a luxury; it's an imperative. The once-crystal-clear boundaries between "work" and "home" have blurred, creating a tapestry of workspaces as diverse as the people who populate them.
Ransomware: To pay or not to pay
Let’s assume for a moment that, one day, perhaps sooner, perhaps later, you will face the reality of a ransomware attack. Chances are that, in the moment, your cybersecurity team will turn to you as the decision maker.
Three NIS2 pitfalls that the government should avoid
NIS2 isn’t the first directive to be translated into legislation, nor will it be the last. When we look at what we can learn from previous legislation, these are the lessons we think the Dutch government should take to heart.
What Hollywood gets wrong about cybersecurity
Hollywood has a knack for dramatizing the digital battlefield. Let’s peel back the Hollywood façade and shine a light on what cybersecurity really looks like in the command centers of SOCs and CSIRTS.
Why critical incident response is the ER of cybersecurity
A Cyber Security Incident Response Team is the emergency room of cybersecurity. You don’t want to need one, but once something bad happens, the ER doctors might just save your life. You don’t want to need critical incident response, but once a cyber incident occurs, you’ll be glad you have a team ready.
What happens when the ON2IT CSIRT jumps into action: A Customer Incident Playback
Prevention should be the holy grail of any cybersecurity strategy, but we know that 100% prevention is not realistic. So, what exactly happens when a serious threat is detected? Using a recent incident as an example, it is enlightening to follow the chain of events that starts when human SOC analysts decide that CSIRT action is required.
NIS2 compliance may prevent 7-million-euro fines
NIS2 has been in effect since January 2023, with a deadline of October 2024 for EU member states to publish and implement policy. Not only does NIS2 dictate new, stricter cybersecurity guidelines, but if European legislators can prove gross negligence, fines for both your company and you as the CEO of the company will be quite significant.
How Zero Trust as a Service reduces the cost of a data breach
In risk management, the formula Risk = Likelihood × Impact is foundational. Here's how it works: Likelihood : The probability of a specific event occurring. Impact
The MGM Resorts attack and its impact on the supply chain
The MGM Resorts Attack led to a ripple effect of consequences that affected not just them, but also their supply chain.
Navigating Zero Trust - Part 1
Over a decade of evolution of Zero Trust has resulted in a number of practical tools and practices to operationalize this strategic approach. The so-called Five Step Model to implement Zero Trust is generally considered to be the best general approach for organizations to start their Zero Trust journey.
The Dynamic Update of Protect Surface Metadata
In our interconnected digital age, robust cybersecurity is as much about understanding what you're defending as it is about the intricacies of the defenses themselves. Think of digital assets as a vast castle.
Zero Trust and the network transformation
Many companies don’t stop to think about the status of their cybersecurity until a problem arises. Whether it’s a sudden transition to remote work or the abrupt implementation or alteration of compliance guidelines, the moment to then start thinking about your cybersecurity will already have passed.
The silver lining of cyber resilience
In the digital age, where the fabric of our interconnected world is woven with threads of data and technology, the imperative for cyber resilience has never been more urgent.
Ladies and gentlemen of the board
Cybersecurity remains a top priority of businesses, but the harsh reality of cybersecurity is that the investment can be hard to sell. The costs are easy to
ON2IT launches new services for implementing Zero Trust successfully
ON2IT announces the launch of three new services: Zero Trust Readiness, Zero Trust Fast Track and Zero Trust Coaching. The new ON2IT services, together referred to as Zero Trust RFC, have been designed to support organizations with successful Zero Trust implementations.
Samantha is leaving
The shortage of staff in the IT market is nothing new: companies struggle to find and maintain good IT staff, a lack of specific knowledge and skills amongst IT staff makes a large number of job ads hard to fill and it’s becoming more and more normal to regularly switch jobs.
The impact of cybersecurity on your organization’s profit
Return on Investment (ROI) in the context of cybersecurity measures is a hot subject. Which makes sense, as technology providers don’t want to position cybersecurity as a cost with no return. But how accurate is that discussion?
The cybersecurity industry’s ‘dirty little secret’
A partner who just collects alerts and then makes leaves fixing the problem in your hands, doesn’t actually get you anywhere. It’s comparable to a security service that sends you a quick message: we received a report of a break-in at your office: good luck with that!
This should keep you up at night as a CEO: cybersecurity on pager duty
Strangely, most companies, including larger organizations, have set up their cybersecurity according to the above pager duty model. Truly incomprehensible, as cold statistics tell you that ransomware, data theft or cyber sabotage are a great threat to continuity than the traditional calamities that we do adequately deal with.
Hackers only need one unguarded minute. On average, you offer 60-150 days.
Software has vulnerabilities that provide hackers with the opportunity to steal data, install ransomware or sabotage your business. Criminal organizations and intelligence services are willing to pay a lot of money for vulnerabilities that (almost) no one knows about. Big bucks (or rather, cryptos) are paid for these zero-days on the so-called dark web, because they offer you an open backdoor just for you
API Security - What you need to know
The 2022 Year-End API ThreatStatsTM Report provides some very interesting insights into the rise of attacks against API endpoints. They have set themselves the
ON2IT Expands its Zero Trust as a Service Cloud Platform to Support the CISA Zero Trust Maturity Model
ON2IT, a leading provider of managed cybersecurity services, announces the addition of the CISA Zero Trust Maturity Model into its Zero Trust as a Service platform, AUXO™. Organizations can use ON2IT’s Zero Trust as a Service platform to strengthen cyber defenses and easily embrace Zero Trust.
Zero Trust’s creator John Kindervag shares his insights with VentureBeat — Part II
The NSTAC and compliance are the big topics in part II of this interview with John Kindervag, done by VentureBeat. In part I of this interview , he touched upon
Zero Trust’s creator John Kindervag shares his insights with VentureBeat — Part I
How do the organizations you work with overcome barriers to adopting and implementing zero trust? John Kindervag: Zero trust, because it’s a strategy
ON2IT expands its Zero Trust as a Service (ZTaaS) platform with support for compliance
ON2IT announced that it has expanded its Zero Trust as a Service (ZTaaS) platform AUXOTM with new features that allow easily meet compliance requirements, such as the NIS2 Directive.
Reducing the Blast Radius of Zero-Days with Zero Trust and XDR
The clock starts ticking as soon as a zero-day vulnerability is disclosed. Cybersecurity teams scramble to shore up their defenses and search for signs of
No More Sucking Chest Wounds
We are too passive. Too afraid of action. Too intimidated to do the right thing for our organization. Let's look at the excuses for this...
The Log4j lessons: so what IS vulnerability management anyway?
When your IT-department is confronted with a serious threat such as Log4j, you should be able to focus on problems that precede the question of whether you should and can patch or not.
The war situation in Ukraine and cyber threats
On February 24, we sent out a security update on the cybersecurity implications of Russia's invasion of Ukraine. In this new bulletin, we give you a status update on the most recent developments.
Lessons learned from over fifty years of combined Zero Trust implementation
In this blog series, we take a look at what lessons we have learned from many years of Zero Trust implementation gathered from six experts.
The war situation in Ukraine and cyber threats
On February 24, we sent out a security update on the cybersecurity implications of Russia's invasion of Ukraine. In this new bulletin, we give you a status update on the most recent developments.
The Log4j lessons: what IS vulnerability management?
When your IT-department is confronted with a serious threat such as Log4j, you should be able to focus on problems that precede the question of whether you should and can patch or not.
The Log4j lessons: If it ain’t broke, fix it now!
The lessons you can learn from Log4j and how to protect yourself better against these vulnerabilities in the future.
Log4j: Frequently Asked Questions
The Log4j vulnerability that was discovered on Thursday, December 9th, is still a pressing issue for many companies. Since its discovery, we’ve received many questions from customers, most of which we have gathered on this FAQ page. If you have any questions regarding the Log4j vulnerability, you can find the answer to many of them here.
Using more security products won’t solve your cybersecurity problem
As we start using more and more products, we also need to implement more security measures. Find out what you can do!
Don’t just cry wolf – Avoid alarm fatigue, use continuous validation
A one-off vulnerability assessment or automated penetration test may serve to raise awareness to gain focus. Still, it also bears a risk of fatigue in that it usually raises a seemingly insurmountably large heap of issues. If you're seeking to take control of and improve an existing situation, don't look once.
John Kindervag, creator of Zero Trust, joins MSSP ON2IT
ON2IT is proud to announce that Zero Trust creator John Kindervag will join ON2IT as Senior VP Cybersecurity Strategy and Group Fellow.
The broken DMZ model
The DMZ model can be found in the physical world, with the DMZ between North and South Korea being the most well-known. The idea of this DMZ is that it is neutral territory. Whenever there needs to be some sort of discussion impacting both parties, they meet in the DMZ. When network operators first started implementing the DMZ model, the idea was same.
Zero Trust: a means and not an end in itself
What is Zero Trust all about? Is it a realistic securitymodel? Is it a means or an end in itself? In this article we discuss the essence of Zero Trust.
Network segmentation is not Zero Trust
Network segmentation can be a tool for a Zero Trust strategy, but isn't Zero Trust in itself. Find out more about the differences between network segmentation and Zero Trust?
Context is key: the data challenge of cybersecurity
One of the biggest challenges within cybersecurity is how to handle the sheer amount of data. Everyone in the field is familiar with the stories of failed SIEM
Security Chief Yuri Bobbert exchanges NN Group for cybersecurity specialist ON2IT
With the appointment of Prof. Dr. Yuri Bobbert as Global Chief Information Security Officer, cybersecurity company ON2IT has acquired a cybersecurity expert with extensive theoretical and practical experience.
ON2IT provides instant support for Cortex XDR by Palo Alto Networks
ON2IT announced that it will host managed services for Palo Alto Networks Cortex, the industry’s only open and integrated AI-based continuous security platform, starting with Cortex XDR.
After a data breach, can you empower your CEO in thirty minutes?
Can your department tell the CEO within 30 minutes after detection of a breach how it happened, which data was impacted, how it was stopped and if all forensic evidence is safeguarded?
The global mission of Zero Trust innovator ON2IT
The limited service model is bound to become extinct. Discover what is in the future for cybersecurity with ON2IT.
ON2IT appoints Ron Myers as CRO
ON2IT announces that Ron Myers has been appointed as CRO. This announcement follows the recent opening of ON2IT’s first US office last October.
How a fitness app became a matter of international security
By combining the Polar Flow data with social media profiles and other public information, Dutch journalists, together with the Bellingcat network for citizen journalism, were able to find names, addresses and photos of no less than 6460 individuals.
ON2IT opens first US office and appoints Kristie Bell CEO
ON2IT announced the opening of its first US office in Plano, Texas. This will strengthen the company’s partnerships with corporate clients and resellers in the North American market.
No articles match your filters right now. Try resetting.