ON2IT - Zero Trust Innovators

Select your region

Talk to us →

Home / Blog / Rob Maas

Rob Maas

Rob Maas

Field CTO, ON2IT

Rob Maas is Field CTO at ON2IT and Product Owner of its AUXO™ platform — the platform built to operationalize Zero Trust. He joined ON2IT in 2015, spending his early years in Professional Security Services, where he built deep hands-on experience across networking, firewalls, Infrastructure as Code, and cloud.

Rob holds an extensive portfolio of Palo Alto Networks certifications, is a Certified Instructor, and was the first Palo Alto Networks Cyber Force Elite in the Netherlands. His Zero Trust credentials include the Forrester ZTX Strategist and CSA CCZT. He created the AUXO Terraform Provider and AUXO MCP Server, hosts Threat Talks Deep Dives, and writes regularly on the ON2IT blog.

By Rob Maas

Articles from Rob

Trends & Reports

You don't need additional AI security tooling | ON2IT Blog

AI vendors are pitching a new generation of security tools. Most organizations don't need them. They need to execute Zero Trust on the stack they already own.

Industrial Technology

Zero Trust for AI Agents

AI agents expand the attack surface. Learn how Zero Trust for AI agents strengthens agentic AI security and protects non-human identities in modern enterprises.

Industrial Technology

OT needs Zero Trust 2.0

The IT/OT convergence flips the script on security. Traditional models such as the Purdue Model were designed for separation. Today’s reality demands something different: a model that ditches static boundaries and kills implicit trust. That’s where Zero Trust 2.0 for OT security comes in.

Zero Trust

The Forgotten Protect Surface: Securing SaaS in a Zero Trust World

Cut through the noise and find out how to turn SaaS from a soft target into a secured stronghold: from shared responsibility to access control, network segmentation, and data in motion.

Zero Trust

Zero Trust isn't "hard" - it's unfocused.

Zero Trust isn’t hard – it’s about focus. Most CISOs struggle because they treat Zero Trust like an all-or-nothing moonshot. In reality, Zero Trust is a strategy applied incrementally to one protect surface at a time, using tools organizations already own.

Opinion

Purdue vs Zero Trust in OT security

The Purdue Model has long served as a foundation for securing OT environments, but its limitations in addressing modern cyber threats are evident. Zero Trust enhances OT security by enforcing strict access controls, continuous monitoring, and micro-segmentation.

Opinion

Zero Trust: A New Year’s resolution worth keeping

As the year draws to a close, it’s time to reflect on the past 12 months and make plans for the year ahead. For those of us in cybersecurity, the question is clear: what did we do to strengthen our security posture this year, and how can we do even better next year?

Business

The crucial role of business alignment in cybersecurity

Though Zero Trust is here to stay, that doesn’t mean implementation is easy. Rob Maas is one of the leading Zero Trust consultants and the Field CTO at ON2IT. In this second part of his blog series he answers the question: what part does business alignment play in cybersecurity implementations?

Threat Intel

VPN-Firewall Integration: A Strategic Analysis

Integrating various network functions within a single device, such as combining VPN (Virtual Private Network) capabilities with firewalls, has become a common practice over the past few years. This consolidation offers benefits in terms of platform security features (i.e. user-based policies and Layer 7 inspection), simplicity and cost-effectiveness.

Opinion

Navigating Zero Trust - Part 1

Over a decade of evolution of Zero Trust has resulted in a number of practical tools and practices to operationalize this strategic approach. The so-called Five Step Model to implement Zero Trust is generally considered to be the best general approach for organizations to start their Zero Trust journey.

Threat Intel

The Log4j lessons: so what IS vulnerability management anyway?

When your IT-department is confronted with a serious threat such as Log4j, you should be able to focus on problems that precede the question of whether you should and can patch or not.

Technology

The Log4j lessons: If it ain’t broke, fix it now!

The lessons you can learn from Log4j and how to protect yourself better against these vulnerabilities in the future.

Trends & Reports

The broken DMZ model

The DMZ model can be found in the physical world, with the DMZ between North and South Korea being the most well-known. The idea of this DMZ is that it is neutral territory. Whenever there needs to be some sort of discussion impacting both parties, they meet in the DMZ. When network operators first started implementing the DMZ model, the idea was same.

Trends & Reports

Network segmentation is not Zero Trust

Network segmentation can be a tool for a Zero Trust strategy, but isn't Zero Trust in itself. Find out more about the differences between network segmentation and Zero Trust?

Managed Security

Context is key: the data challenge of cybersecurity

One of the biggest challenges within cybersecurity is how to handle the sheer amount of data. Everyone in the field is familiar with the stories of failed SIEM

Browse all articles