Rob Maas is Field CTO at ON2IT and Product Owner of its AUXO™ platform — the platform built to operationalize Zero Trust. He joined ON2IT in 2015, spending his early years in Professional Security Services, where he built deep hands-on experience across networking, firewalls, Infrastructure as Code, and cloud.
Rob holds an extensive portfolio of Palo Alto Networks certifications, is a Certified Instructor, and was the first Palo Alto Networks Cyber Force Elite in the Netherlands. His Zero Trust credentials include the Forrester ZTX Strategist and CSA CCZT. He created the AUXO Terraform Provider and AUXO MCP Server, hosts Threat Talks Deep Dives, and writes regularly on the ON2IT blog.
Articles from Rob
You don't need additional AI security tooling | ON2IT Blog
AI vendors are pitching a new generation of security tools. Most organizations don't need them. They need to execute Zero Trust on the stack they already own.
Zero Trust for AI Agents
AI agents expand the attack surface. Learn how Zero Trust for AI agents strengthens agentic AI security and protects non-human identities in modern enterprises.
OT needs Zero Trust 2.0
The IT/OT convergence flips the script on security. Traditional models such as the Purdue Model were designed for separation. Today’s reality demands something different: a model that ditches static boundaries and kills implicit trust. That’s where Zero Trust 2.0 for OT security comes in.
The Forgotten Protect Surface: Securing SaaS in a Zero Trust World
Cut through the noise and find out how to turn SaaS from a soft target into a secured stronghold: from shared responsibility to access control, network segmentation, and data in motion.
Zero Trust isn't "hard" - it's unfocused.
Zero Trust isn’t hard – it’s about focus. Most CISOs struggle because they treat Zero Trust like an all-or-nothing moonshot. In reality, Zero Trust is a strategy applied incrementally to one protect surface at a time, using tools organizations already own.
Purdue vs Zero Trust in OT security
The Purdue Model has long served as a foundation for securing OT environments, but its limitations in addressing modern cyber threats are evident. Zero Trust enhances OT security by enforcing strict access controls, continuous monitoring, and micro-segmentation.
Zero Trust: A New Year’s resolution worth keeping
As the year draws to a close, it’s time to reflect on the past 12 months and make plans for the year ahead. For those of us in cybersecurity, the question is clear: what did we do to strengthen our security posture this year, and how can we do even better next year?
The crucial role of business alignment in cybersecurity
Though Zero Trust is here to stay, that doesn’t mean implementation is easy. Rob Maas is one of the leading Zero Trust consultants and the Field CTO at ON2IT. In this second part of his blog series he answers the question: what part does business alignment play in cybersecurity implementations?
VPN-Firewall Integration: A Strategic Analysis
Integrating various network functions within a single device, such as combining VPN (Virtual Private Network) capabilities with firewalls, has become a common practice over the past few years. This consolidation offers benefits in terms of platform security features (i.e. user-based policies and Layer 7 inspection), simplicity and cost-effectiveness.
Navigating Zero Trust - Part 1
Over a decade of evolution of Zero Trust has resulted in a number of practical tools and practices to operationalize this strategic approach. The so-called Five Step Model to implement Zero Trust is generally considered to be the best general approach for organizations to start their Zero Trust journey.
The Log4j lessons: so what IS vulnerability management anyway?
When your IT-department is confronted with a serious threat such as Log4j, you should be able to focus on problems that precede the question of whether you should and can patch or not.
The Log4j lessons: If it ain’t broke, fix it now!
The lessons you can learn from Log4j and how to protect yourself better against these vulnerabilities in the future.
The broken DMZ model
The DMZ model can be found in the physical world, with the DMZ between North and South Korea being the most well-known. The idea of this DMZ is that it is neutral territory. Whenever there needs to be some sort of discussion impacting both parties, they meet in the DMZ. When network operators first started implementing the DMZ model, the idea was same.
Network segmentation is not Zero Trust
Network segmentation can be a tool for a Zero Trust strategy, but isn't Zero Trust in itself. Find out more about the differences between network segmentation and Zero Trust?
Context is key: the data challenge of cybersecurity
One of the biggest challenges within cybersecurity is how to handle the sheer amount of data. Everyone in the field is familiar with the stories of failed SIEM