Three out of four firewall rule sets ON2IT’s SOC inherits from new customers share the same blind spots, and none of the fixes cost extra licensing.

In this episode, Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with Jelle Konings, security optimization specialist in ON2IT’s Security Operations Center, to walk through the mistakes his team finds on almost every inherited network: no logging enabled, no identity tied to traffic, no default deny rule at the bottom of the rule base, and port-based rules standing in for real application control. Most environments he inherits sit around 30 to 40 percent application-based policy coverage against a 60 to 80 percent target.

You will hear what to check first when you inherit a firewall, how long a realistic clean-up takes (weeks, months, sometimes over a year), and why an encrypted VPN tunnel riding on port 443 can move data out the door without a single alert firing.


🔗 Episode resources, transcript and show notes: https://threat-talks.com 
📝 Read the companion blog post: https://threat-talks.com/blog/four-firewall-mistakes-still-wrecking-networks-in-2026/
🎙️ Subscribe on Spotify and Apple Podcasts, links below.

Threat Talks is a podcast by ON2IT cybersecurity and AMS-IX. We delve deep into the dynamic world of cybersecurity, one episode at a time. New episode every Tuesday.

#ThreatTalks #ZeroTrust #FirewallSecurity #NetworkSecurity #CyberSecurity #InfoSec

Chapters: 

00:00 Cold open: the top firewall mistakes of 2025
00:21 Meet Jelle Konings, security optimization specialist
01:16 Mistake 1: No visibility into your network
03:36 Mistake 2: Skipping User-ID mapping
06:01 Mistake 3: No default deny rule
07:44 Fixing it: from logs to default deny
09:09 Bonus mistake: port-based vs. application-based rules
13:20 Will 2026 be any different?

Podden och tillhörande omslagsbild på den här sidan tillhör Threat Talks. Innehållet i podden är skapat av Threat Talks och inte av, eller tillsammans med, Poddtoppen.