Zero Trust: Why protection inside your perimeter is vital to cyber security success – Webinar Replay

Louis Zezeran 30. juuli 2026

Imagine a railway engineer sitting in a field in southern Estonia, laptop open, repairing critical infrastructure systems — authenticated and secured in exactly the same way as a colleague sitting at headquarters in Tallinn. No special exceptions, no trusted office network, no “you’re inside, so you’re fine.” That picture, painted by host Louis Zezeran at the top of this episode of the NEVERHACK Cybercast, captures what zero trust really means in practice. And by the end of the episode, you’ll hear from the man who actually made it happen. 

This live webinar episode brings together three perspectives on one of the most talked-about — and most misunderstood — concepts in cybersecurity: Domenico Iandoli, network security manager at NEVERHACK Italy; Jonne Tuomela of Netskope; and Tõnu Tammer, Chief Technology Officer of Estonian Railways and former head of Estonia’s national CERT. Together they take zero trust from academic definition to vendor technology to a genuine national-scale implementation — one bold enough to test whether the trains keep running if Estonia’s internet connection to the outside world is severed entirely. 

Why now? The AI has changed the game 

The episode starts with the “why”: a 2025 Gartner report on Continuous Threat Exposure Management (CTEM). The uncomfortable conclusion is that the traditional security routine — find a CVE, install the patch, move to the next one — is now a losing race. As Louis puts it, modern AI models will out-patch you; they will find your vulnerabilities before you do. Gartner predicts that by 2028, more than half of significant threat findings won’t come from CVEs or software flaws at all. They’ll come from cloud misconfigurations, identity gaps, and unexpected interactions between integrated systems. 

That shift demands a different architecture — one where a single technical exploit getting through is not “one and done.” That architecture is zero trust. 

Part one: What zero trust actually is (and isn’t) 

Domenico Iandoli sets the baseline with refreshing bluntness: zero trust is not a product. You cannot install it, and any vendor selling a box labelled “zero trust” deserves scepticism. It is a shift in the security model — a way of designing access to resources, and above all, a journey that develops over months and years, not days. 

The old model, he explains, is the “castle and moat”: defend the perimeter, and trust everything inside it. The problem is obvious — if an attacker gets inside, they can go anywhere. Zero trust flips the assumption: design your defences as if the attacker is already inside. Every piece of data and every service is a resource. Every communication must be secured regardless of network location. Access is granted per session, based on dynamic policy — who you are, where you’re connecting from, what you’re asking for, and the security posture of your device. 

Domenico adds a dimension many discussions miss: identity is no longer just about humans. Machine identities — service accounts, API keys, and increasingly AI agents — now outnumber human ones. Agentic AI performing machine-to-machine transactions with no human in the loop is exactly the kind of thing that needs zero trust treatment. He also flags “shadow AI” as one of today’s most dramatic blind spots: employees pasting sensitive company data into AI tools that IT has never seen or sanctioned. If you can’t see it, you can’t control it. 

His practical advice for getting started? Most customers begin with Zero Trust Network Access (ZTNA) — replacing the legacy VPN. A classic VPN is the castle-and-moat model incarnate: once you’re in, you can go everywhere, and the VPN concentrator itself is a publicly exposed target with a long history of critical CVEs. ZTNA removes that exposure entirely. Alongside it, he highlights microsegmentation — limiting the “blast radius” so that when something is hit, the damage is contained — and consolidation: bringing firewall-as-a-service, secure web gateway, CASB and DLP together onto a single SASE platform, so your team spends time writing policy instead of integrating tools. 

Part two: How the technology works 

Jonne Tuomela from Netskope picks up exactly where Domenico leaves off, untangling the terminology. SASE (Secure Access Service Edge) is the broad framework: connecting users to applications wherever they live — private data centre, cloud, or SaaS — and applying policy along the way. ZTNA is the component of SASE that handles private applications without exposing them to the internet. And the trust broker is the middleman every connection passes through, where policy gets applied. 

What makes this genuinely different from a VPN with better marketing? The depth of the checks. Jonne walks through the engines that evaluate every single transaction: identity (is this really John from Finance?), device trust (managed device or BYOD?), location (home office, work office — or North Korea?), application trust, and crucially, the specific instance of the application. A personal OneDrive and a corporate OneDrive share the same URL — only by looking into the data itself can you tell them apart and stop sensitive corporate files leaking into personal accounts. 

One of the most human insights of the episode is Netskope’s philosophy on blocking. Flat-out blocking sites, Jonne argues, has never been a good strategy with your own workforce. Instead, the platform can coach users in real time: a pop-up warns that an upload may contain sensitive data and asks whether they want to proceed — creating both a moment of reflection and an audit trail. Truly sensitive data still gets blocked, but the goal is to be more than a blocking technology. 

Jonne is also honest about the limits: any DLP vendor who claims their solution is effortless, pre-configured, and free of false positives is waving a red flag. Every company’s data landscape is different, and real work is required to build policies on the vendor’s foundation. 

Part three: Zero trust on the railways 

Then comes the proof that all of this is achievable — not by a Silicon Valley startup, but by a 100% state-owned railway company more than 155 years old. Tõnu Tammer joined Estonian Railways after five-plus years leading Estonia’s national CERT, and making this transformation was literally a condition of him taking the job. He wanted to prove that what he’d been preaching could be done in a heavy, regulated, legacy-laden industrial environment. 

And legacy there is. In a safety-critical rail environment, replacing four Windows computers can cost a million euros once regulatory safety procedures are factored in. Which is exactly why the patching mantra fails there. As Tõnu memorably puts it: “We’ve used this mantra for the last twenty-plus years and we’ve failed miserably. Beating a dead cow harder doesn’t produce more milk.” 

His team’s approach was pragmatic: start small. A four-month proof of concept, tested internally on IT, before any switchover. The resulting stack consolidates on two vendors — Microsoft and Cloudflare — a deliberate move after discovering the company was somehow running four different antivirus products. Consolidation, in his view, isn’t vendor lock-in; it makes you a strategic partner with real leverage. When he brought Cloudflare an idea, it was delivered within a week. 

The headline achievement, though, is resilience. Estonian Railways is, by Tõnu’s account, the only company in Estonia to have tested its services in full isolation mode — simulating the scenario where every external cable connecting Estonia to the internet is cut. Using Starlink with a content delivery network in front of it, the essential services stay up. Nobody streams YouTube in that scenario, but the trains keep running. That’s the point. 

He’s equally candid about what was hard: shared computers. The “P” in PC stands for personal, and zero trust tooling assumes a one-to-one link between machine and user — an assumption that breaks when shift workers share terminals and identity flips constantly. It took time for the technology to catch up. Would he reconsider the choice? “Definitely no.” 

His parting advice for anyone evaluating vendors: interrogate what “zero trust” actually means in each offering — for some vendors it’s just a reinvented word for segmentation. Every SASE and zero trust vendor has a niche; match it to your business needs and make an educated choice. And as for zero trust itself? Like the old legend that Tallinn must never be finished, it’s a journey that never gets done — there’s always a further tightening, another policy. But paired with continuous threat exposure management, the effect is powerful: the castle disappears. If attackers can’t see you, they can’t target you. 

Listen now 

Whether you’re a CISO planning a transformation, an engineer wrestling with a legacy VPN, or a business leader wondering why security keeps asking for budget, this episode delivers a complete arc: the why, the how, and the proof. Listen to the full episode now, and subscribe so you don’t miss the next NEVERHACK Cybercast. And if you’re anywhere near the Baltics on September 10th, join us at the Nordic-Baltic Security Summit in Tallinn — the premier security event of the region, hosted by Louis Zezeran. Tickets and details at nbss.ee. 

Jaga

Märksõnad

Märksõnad

Jaga

Viimased postitused

23. juuli 2026

Nutikad kodumasinad võivad avada ukse küberkurjategijatele

Veel kümmekond aastat tagasi tähendas turvaline kodu eelkõige korralikku lukku ja võib-olla ka valvesüsteemi. Tänapäeval tähendab kodu kaitsmine aga palju enamat. Üha suurem osa meie elust toimub digitaalses keskkonnas ning koos sellega on muutunud ka turvariskid. Kurjategijad ei pea enam füüsiliselt kellegi koju sisse murdma,  piisab vaid ligipääsust ühele internetti ühendatud seadmele. Robotmuruniidukid, robottolmuimejad, turvakaamerad, […]

Loe edasi
2. juuli 2026

Kuidas tagada turvaline AI ja pilveteenuste kasutamine

Netskope aitab muuta nähtamatud riskid nähtavaks Pilveteenused, SaaS-rakendused ja tehisintellekt on saanud meie igapäevase töö oluliseks osaks. Küsimus ei ole enam isegi selles, kas töötajad neid kasutavad, vaid selles, kas organisatsioon suudab seda kasutust turvaliselt omaltpoolt juhtida. Täna on võimalik töötada kõikjal- kontoris, kodus, kliendi juures ja liikvel olles. Andmed liiguvad Microsoft 365, Google Workspace’i, […]

Loe edasi
2. juuli 2026

Üks turvanõrkus võib peatada kogu tootmisliini

Eesti tööstusettevõtted on viimastel aastatel teinud suure arenguhüppe. Automatiseeritud tootmisliinid, ühendatud seadmed, pilveteenused ja digitaliseeritud tarneahelad aitavad tõsta efektiivsust ning konkurentsivõimet. Kuid mida rohkem sõltub tootmine digitaalsest taristust, seda suuremaks muutub ka küberturvalisuse roll. Neverhack Estonia juhatuse liikme Rita Käit’i sõnul ei ole Eesti tööstusettevõtete suurim väljakutse enam tehnoloogia puudumine, vaid tervikpildi puudumine. „Paljud ettevõtted […]

Loe edasi