{"id":40040,"date":"2026-08-27T18:14:59","date_gmt":"2026-08-27T12:14:59","guid":{"rendered":"https:\/\/www.amcham.kg\/?post_type=membernews&#038;p=40040"},"modified":"2026-08-27T18:17:51","modified_gmt":"2026-08-27T12:17:51","slug":"applying-ztna-in-the-financial-sector-green-light-expert-speaks-at-the-national-bank-of-kyrgyzstan-s-cyberfinance-2026-forum","status":"publish","type":"membernews","link":"https:\/\/www.amcham.kg\/en\/membernews\/applying-ztna-in-the-financial-sector-green-light-expert-speaks-at-the-national-bank-of-kyrgyzstan-s-cyberfinance-2026-forum\/","title":{"rendered":"Applying ZTNA in the Financial Sector: Green Light Expert Speaks at the National Bank of Kyrgyzstan\u2019s CYBERFINANCE-2026 Forum"},"content":{"rendered":"<section class=\"l-section wpb_row height_custom\"><div class=\"l-section-h i-cf\"><div class=\"g-cols vc_row via_flex valign_top type_default stacking_default\"><div class=\"vc_col-sm-12 wpb_column vc_column_container\"><div class=\"vc_column-inner\"><div class=\"wpb_wrapper\"><div class=\"wpb_text_column\"><div class=\"wpb_wrapper\"><p><span style=\"font-weight: 400;\">On July 21, the CYBERFINANCE-2026 forum, organized by the National Bank of Kyrgyzstan, took place at the Razzakov Kyrgyz State Technical University (KSTU) in Bishkek. Systems integrator Green Light acted as an official partner, and Baisal Sheraliev, Senior Security Engineer at Green Light, delivered a report on Zero Trust Network Access (ZTNA) in the financial sector. Below is a breakdown of the core concepts presented.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The traditional corporate network perimeter in Kyrgyzstan\u2019s financial sector has largely dissolved. The rollout of the digital som, widespread cloud adoption, open APIs, and various fintech integrations continuously expand the attack surface. Furthermore, remote work and third-party vendor connections push sensitive data far beyond the bank&#8217;s secure boundaries. Consequently, trust can no longer be granted simply because a device is located on the internal network. Security must be rooted in strict identity verification, contextual awareness, and the principle of least privilege for every single request.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Traditional VPNs are now widely considered obsolete because they grant users access to the entire network rather than specific resources. If an attacker breaches the perimeter, they gain the freedom to move laterally across the infrastructure. Zero Trust Network Access (ZTNA) replaces this legacy mechanism by granting access strictly on a per-application basis. All other corporate services remain hidden from the outside world and invisible without explicit authorization. Under ZTNA, a trust broker dynamically evaluates access for every new session, factoring in both user identity and device posture.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This architecture is already standard practice in high-load industries. Global airlines, for instance, use ZTNA to provide thousands of worldwide contractors with secure access to critical Global Distribution Systems (GDS). Users work entirely through their web browsers without VPN clients. The internal network remains fully concealed, lateral movement is prevented, and every action is recorded in audit logs. For the banking sector, this is the optimal operational model for managing third-party vendor access.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Today, however, securing human access addresses only part of the risk. Digitalization introduces entirely new threat vectors where the primary actors are autonomous AI agents. A modern AI agent is fundamentally different from a standard chatbot: it can independently set sub-tasks, invoke tools, make decisions, and operate autonomously within an IT infrastructure. In the financial sector, these solutions are already automating SOC analysts&#8217; workflows, anti-fraud systems, and complex customer service scenarios. The underlying risk is that each of these agents requires direct access to the bank\u2019s databases and internal systems.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The scale of this shift is significant: the number of autonomous agents is projected to grow by 85% over the next year. Already, machine identities outnumber human employees in a typical organization by a ratio of 80 to 1. Granting AI agents broad network access and standing privileges can lead to massive security incidents, as machines operate in milliseconds and instantly replicate errors. We are also seeing highly specific threats emerge: <\/span><i><span style=\"font-weight: 400;\">prompt injection<\/span><\/i><span style=\"font-weight: 400;\">, for instance, allows hackers to embed hidden instructions within data to force an AI to execute malicious commands. The abuse of legitimate tools, agent token theft, and standing privileges combine to create an enormous blast radius in the event of a compromise.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To mitigate these risks, core Zero Trust principles must be extended to AI agents, treating them as full-fledged network entities. Every AI must have a verifiable identity strictly tethered to its human owner. Instead of standing permissions, systems should issue short-lived Just-in-Time (JIT) tokens granted exclusively for specific tasks\u2014a concept known as Zero Standing Privileges (ZSP). Additionally, a unified MCP (Model Context Protocol) gateway must tightly restrict the toolkit available to the agent and rigorously filter its inputs. Every API call or data request made by an AI must be continuously logged to ensure auditability and behavioral control.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Implementing this defense-in-depth architecture requires strict sequencing. For a bank, the roadmap begins with a comprehensive inventory of all network entities: humans, machines, and AI agents. The next step is enforcing strong authentication, notably phishing-resistant MFA. This is followed by replacing legacy VPNs with ZTNA for targeted, application-level access. The final stages involve microsegmentation, deploying guardrails for AI agents, and establishing continuous behavioral monitoring.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Securely managing autonomous AI entities and protecting sensitive data relies entirely on a Zero Trust architecture. Strict identity verification, minimal privileges, and total traceability form the foundation that enables the financial sector to deploy innovations without expanding its attack surface.<\/span><\/p>\n<p><i><span style=\"font-weight: 400;\">For its significant contribution to organizing and conducting the CYBERFINANCE-2026 cyber exercises, Green Light was awarded a letter of appreciation from the National Bank of the Kyrgyz Republic.<\/span><\/i><\/p>\n<\/div><\/div><div class=\"w-separator size_small\"><\/div><div class=\"w-slider style_none fit_scaledown nav_none count_3\"><div class=\"w-slider-h\"><div class=\"royalSlider\"><div class=\"rsContent\"><a class=\"rsImg\" data-rsw=\"771\" data-rsh=\"1024\" href=\"https:\/\/www.amcham.kg\/wp-content\/uploads\/2026-08-04-10.47.31-771x1024.jpg\"><span data-alt=\"\"><\/span><\/a><\/div><div class=\"rsContent\"><a class=\"rsImg\" data-rsw=\"1024\" data-rsh=\"576\" href=\"https:\/\/www.amcham.kg\/wp-content\/uploads\/1-1-1-1024x576.png\"><span data-alt=\"\"><\/span><\/a><\/div><div class=\"rsContent\"><a class=\"rsImg\" data-rsw=\"1024\" data-rsh=\"683\" href=\"https:\/\/www.amcham.kg\/wp-content\/uploads\/dsc03823-2-1024x683.jpeg\"><span data-alt=\"\"><\/span><\/a><\/div><\/div><img decoding=\"async\" data-src=\"https:\/\/www.amcham.kg\/wp-content\/uploads\/2026-08-04-10.47.31-771x1024.jpg\" width=\"771\" height=\"1024\" alt src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" style=\"--smush-placeholder-width: 771px; --smush-placeholder-aspect-ratio: 771\/1024;\"><\/div><div class=\"w-slider-json\" onclick='return {&quot;autoScaleSlider&quot;:true,&quot;addActiveClass&quot;:true,&quot;loop&quot;:true,&quot;fadeInLoadedSlide&quot;:false,&quot;slidesSpacing&quot;:0,&quot;imageScalePadding&quot;:0,&quot;numImagesToPreload&quot;:2,&quot;arrowsNav&quot;:true,&quot;arrowsNavAutoHide&quot;:false,&quot;transitionType&quot;:&quot;move&quot;,&quot;transitionSpeed&quot;:250,&quot;block&quot;:{&quot;moveEffect&quot;:&quot;none&quot;,&quot;speed&quot;:300},&quot;thumbs&quot;:{&quot;fitInViewport&quot;:false,&quot;firstMargin&quot;:false,&quot;spacing&quot;:4},&quot;controlNavigation&quot;:&quot;none&quot;,&quot;autoScaleSliderWidth&quot;:771,&quot;autoScaleSliderHeight&quot;:1024}'><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/section>\n","protected":false},"author":10,"featured_media":40066,"parent":0,"template":"","class_list":["post-40040","membernews","type-membernews","status-publish","has-post-thumbnail","hentry"],"better_featured_image":{"id":40066,"alt_text":"","caption":"","description":"","media_type":"image","media_details":{"width":500,"height":500,"file":"green-light.png","filesize":35373,"sizes":{"medium":{"file":"green-light-300x300.png","width":300,"height":300,"mime-type":"image\/png","filesize":15430,"source_url":"https:\/\/www.amcham.kg\/wp-content\/uploads\/green-light-300x300.png"},"thumbnail":{"file":"green-light-150x150.png","width":150,"height":150,"mime-type":"image\/png","filesize":6092,"source_url":"https:\/\/www.amcham.kg\/wp-content\/uploads\/green-light-150x150.png"},"us_200_150":{"file":"green-light-150x150.png","width":150,"height":150,"mime-type":"image\/png","filesize":6092,"source_url":"https:\/\/www.amcham.kg\/wp-content\/uploads\/green-light-150x150.png"}},"image_meta":{"aperture":"0","credit":"","camera":"","caption":"","created_timestamp":"0","copyright":"","focal_length":"0","iso":"0","shutter_speed":"0","title":"","orientation":"0","keywords":[],"alt":""}},"post":40040,"source_url":"https:\/\/www.amcham.kg\/wp-content\/uploads\/green-light.png"},"acf":[],"_links":{"self":[{"href":"https:\/\/www.amcham.kg\/en\/wp-json\/wp\/v2\/membernews\/40040","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.amcham.kg\/en\/wp-json\/wp\/v2\/membernews"}],"about":[{"href":"https:\/\/www.amcham.kg\/en\/wp-json\/wp\/v2\/types\/membernews"}],"author":[{"embeddable":true,"href":"https:\/\/www.amcham.kg\/en\/wp-json\/wp\/v2\/users\/10"}],"version-history":[{"count":5,"href":"https:\/\/www.amcham.kg\/en\/wp-json\/wp\/v2\/membernews\/40040\/revisions"}],"predecessor-version":[{"id":40075,"href":"https:\/\/www.amcham.kg\/en\/wp-json\/wp\/v2\/membernews\/40040\/revisions\/40075"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.amcham.kg\/en\/wp-json\/wp\/v2\/media\/40066"}],"wp:attachment":[{"href":"https:\/\/www.amcham.kg\/en\/wp-json\/wp\/v2\/media?parent=40040"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}