
Threat Talks · 2026-07-21 · 14 min
Three out of four firewall rule sets ON2IT’s SOC inherits from new customers share the same blind spots, and none of the fixes cost extra licensing. In this episode, Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with Jelle Konings, security optimization specialist in ON2IT’s Security Operations Center, to walk through the mistakes his team finds on almost every inherited network: no logging enabled, no identity tied to traffic, no default deny rule at the bottom of the rule base, and port-based rules standing in for real application control. Most environments he inherits sit around 30 to 40 percent application-based policy coverage against a 60 to 80 percent target. You will hear what to check first when you inherit a firewall, how long a realistic clean-up takes (weeks, months, sometimes over a year), and why an encrypted VPN tunnel riding on port 443 can move data out the door without a single alert firing. Episode resources, transcript and show notes: Read the companion blog post: ️ Subscribe on Spotify and Apple Podcasts, links below. Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.