Louis Zezeran
19. aug 2026
Before the Firewall: Ronnie Jaanhold on 25 Years of Cybersecurity — and What History Tells Us About What’s Coming
There is a moment early in this episode of the NEVERHACK Estonia Cybercast where the whole shape of the cybersecurity industry becomes suddenly, uncomfortably clear.
Ronnie Jaanhold is describing his teenage bedroom. There was an internet service provider operating out of an office upstairs in his building, so he did what any curious kid with a soldering-iron instinct would do: he ran a coax cable down from their office into his room and paid them a fixed monthly fee. “Basically it was their coffee budget,” he says. While everyone else was listening to modems whistle at 56k, he had broadband — and, more importantly, he had a network to explore.
What he found on it was a machine labelled Love. Across the street sat a radio station of the same name, and this was its studio computer. It had open shares. One of them held text files from the national news agency — the actual copy the presenters read out on the hour. Ronnie discovered he could not only read those files. He could write them.
So he did. He wrote news, then listened to the radio as it was read out live. “The news went weirder and weirder,” he says, “up to a point when they discovered it.” No investigation. No forensics. The share simply disappeared one day. Nobody ever knocked on his door.
That story is funny. It is also a complete diagnosis of an era. As host Louis Zezeran points out, two things had to be true for it to happen: the ISP’s network was flat enough that a residential customer could reach straight into another customer’s systems, and there was no logging, no network detection, nothing that could reconstruct what had occurred. Both of those things are unthinkable today. Both were entirely normal then.
The internet was built by optimists
Ronnie’s explanation for why is one of the sharpest lines in the episode. The philosophy of the internet, he notes, comes out of the 1960s — an era of drugs and free love and radical trust — and that mindset was carried straight into the protocols engineers actually built in the 1980s. “We have been patching that up for the past forty or so [years].”
This is the frame the entire conversation hangs on. Security was not designed out of the internet by accident or negligence. It was never designed in, because the people who built it were solving a completely different problem: how do we connect, not how do we defend.
When cybersecurity meant three things
Ask Ronnie what cybersecurity was when he started and the answer is refreshingly short. Antivirus. Firewalls. Encryption. “These were almost almost it.”
And even encryption, which everyone took very seriously, had an obvious limit. “There are multiple ways to get the password out of a person and bypass all the crypto,” he says. “You just have to use a big enough wrench.”
Compare that to a modern stack — EDR, XDR, DLP, identity governance, SIEM, SOC services, attack surface management — and the expansion is dizzying. But the expansion is not the interesting part. What changed the industry was not technology. It was money.
In the early days, Ronnie says, hacking simply wasn’t about money. People broke into things for fun, for curiosity, for status. “But today that crossover has been seriously made. This is business. It’s a criminal business, and it drags criminal people and criminal mindset and violence into the business world. There’s money, right?”
That single shift explains almost everything that followed: professionalisation, ransomware-as-a-service, persistence, exfiltration, extortion. In 2006, Ronnie notes, an incident mostly meant downtime — a self-propagating worm, a spam flood, a service that broke. “Not owned by a hacker per se, but something.” Nobody was quietly maintaining access, mapping your data, and calling home to a command-and-control server. There was no reason to. There was nothing to cash out.
The lesson every seller of security already knows
One of the most quietly useful passages in the episode is Ronnie’s answer to whether security was a hard sell in Estonia. His answer applies to every market on earth.
“Overall, security sell is a tough sell. That hasn’t changed too much. People for some reason need to experience the bad thing before they go for insurance, before they go for protection. That’s in human nature. You can tell a child ten times that the stove is hot — he or she will believe you when they have touched it.”
If you have ever tried to get budget approved for a control that prevents an incident that has not happened yet, you know this is the entire problem in one sentence. Ronnie’s slightly hopeful coda: “This is on its path to a change.” Regulation, board-level attention, and the sheer volume of public breaches are doing what argument alone never could.
Choose the vendor, not just the product
This is where the episode turns genuinely practical, and it comes from a scar.
Ronnie’s company built its early business as a McAfee partner — a deliberate choice, not a random one. McAfee was enterprise-focused, matched their customer base, and had a portfolio broad enough (endpoint, firewall, DLP, encryption, anti-spam, server products) that a small partner could cover most needs from one vendor with one central management console.
Then Intel acquired McAfee. And Ronnie, watching closely, could not construct a business rationale for it. “What was their plan to do with McAfee, and what did that mean for the McAfee user base? That was also questionable. Surely they were not able to execute anything good.” Intel eventually sold it on. The brand fragmented and reappeared under a new name.
The lesson he took from it now shapes how he manages NEVERHACK Estonia’s portfolio: technology assessment is only one input. “The technology can be fancy… but not much of a personality.” You also have to understand the organisation behind it. Who owns it? How is it managed? Where are they heading in a couple of years? “You would then start to understand how the stuff will most probably evolve.”
For anyone doing vendor due diligence, that is a checklist item most procurement processes skip entirely — and it is the one that determines whether your platform is still supported in five years.
When the technology just isn’t ready yet
The MDM story is a useful corrective to anyone who assumes a security category works simply because it exists. Ronnie’s team carried AirWatch when it was still a startup, in the era of the first iPhones and half-smart Symbian devices. The technical challenge was brutal: Android fragmented across countless manufacturers, versions and vendor tweaks; iOS locked down and initially app-less; Symbian a standard designed by committee.
His verdict on that generation of the category is blunt. “Most of the time it was crap. It didn’t actually work.”
Today, with standardisation in place and Microsoft covering much of the ground natively, mobile management genuinely works. And yet, as Louis observes, it is still the last piece customers put in. Endpoint protection for laptops is well understood, server protection is well understood — and then people wave a hand and say the phones will probably be fine. They aren’t.
How to sell to people who hate being sold to
The final third of the conversation is essentially a masterclass in trust, and it will be recognisable to anyone working in a technical field.
“A technical audience — and not only a technical audience — hate sales,” Ronnie says. “They get allergic to sales pitches and PowerPoints.”
What he actually wants from technology partners is inverted from the standard playbook: teach the problem first. “You’re an expert. Teach us about the problem itself.” Talk about the product, yes — but don’t overdo it in the first meeting. Then let the customer test it, because they are going to test it anyway.
Louis adds a small story with a big lesson. A NEVERHACK colleague told him that the competitive slides at the end of the deck are not there to be presented — they are there as backup, in case a customer asks. “Oh, they’re just there as a backup. I’m not here to click through these slides and say how good we are.” The result comes out far more organically.
Ronnie’s own summary of the entire commercial philosophy fits in four words: be helpful and honest.
He is equally clear on why local partners aren’t going away in a globalised market. The further away your technology provider sits, the harder real collaboration becomes — and nobody wants to run their security relationship through a helpdesk ticket queue. Local partners understand the surroundings, the business context, the culture and the language. And in a market the size of Estonia, trust is both an enormous asset and a serious obligation: “These are promises that you make. You have to keep them upright. You have to be there for those promises.”
Why this episode matters now
The reason Louis wanted this conversation in the first place was AI. Everything is being flipped on its head, day in and day out, and the temptation is to treat that as unprecedented.
It isn’t — not entirely. This episode is a reminder that we have been here before: a new technology arrives built for capability rather than safety, an open and trusting era follows, criminals work out how to monetise it, and defence spends the next two decades catching up. The specific tools change constantly. The human patterns — the reluctance to buy insurance, the allergy to being sold to, the need for someone local you can actually trust — barely move at all.
If you work in security, buy security, or sell it, that’s a useful thing to have straight in your head before the next wave.
Listen to the full episode now on SoundCloud and wherever you get your podcasts.
Visit the NEVERHACK website for more from the Cybercast, and subscribe so you don’t miss the next one.
Ronnie and Louis are planning more two-handed conversations like this — if there’s a topic you want them to tackle, reach out to either of them on LinkedIn.