The masked ball in your network.
Getting in is not security.
You decide exactly who gets in. But behind the door everyone wears a mask: no identity, no control, and everybody is listening. This is precisely where most “zero trust” solutions stop.
Video in German
Your network is a masked ball
What you will learn
- Why a zero-trust VPN only guards the door: the difference between user → LAN and user → service
- Four signs that tell you a door-only solution is what you have in your own stack
- The forgotten half: server to server, backups, ERP to MES, OT to IT — traffic that runs through no VPN and never identifies itself
- Why OT devices wear masks they technically cannot take off — and how IEC 62443 maps out the answer with zones and conduits
- The four rules of real zero trust: mutual proof, end to end, service instead of network, centrally governed for every participant
- Why “cannot be found” is worth more than “well protected”
The distinction almost nobody makes
User → LAN
Access to the network
One login, many reachable targets.
User → service
Access to the resource
One proven connection. Everything else stays unreachable.
A ball without masks — the four rules
01
Both sides prove it
Mutual authentication instead of trusting an IP address.
02
End to end
No cleartext leg, nobody listening in.
03
Service, not network
Not permitted means: not even discoverable.
04
Everyone, centrally
Humans and machines, governed in one place.
Servers wear masks too.
Take the masks off the whole room: mutual proof, end to end, service instead of network — for every participant, not just the guest at the door.
Who this is written for
IT leadership, network and security architects, OT and production IT. More technically demanding than whitepaper 01.
Rather ask us directly?
30 minutes, free, no slide deck. We look at your network and tell you honestly where the holes line up.
Book a first call