
ZTNA in the financial sector: a Green Light expert speaks at the CYBERFINANCE-2026 forum of the National Bank of the Kyrgyz Republic
Baisal Sheraliev, Senior Security Engineer at Green Light, on the zero trust concept in banking
On 21 July, the CYBERFINANCE-2026 forum organised by the National Bank of Kyrgyzstan took place in Bishkek at the I. Razzakov Kyrgyz State Technical University. Systems integrator Green Light was a partner of the event, and the company's expert, Senior Security Engineer Baisal Sheraliev, presented a talk on the Zero Trust Network Access approach to network security in the financial sector.
The familiar corporate network perimeter in Kyrgyzstan's financial sector has dissolved for good: the roll-out of the digital som, the use of cloud services, open APIs and assorted fintech integrations keep widening the possible attack surface. On top of that, remote work and the onboarding of external contractors carry sensitive data far beyond the bank's protected boundary. Under these conditions trust can no longer be granted simply because a device sits on the internal network. Security has to rest on strict identity verification, on context, and on least privilege for every single request.
This is exactly why the traditional VPN-based approach is now considered obsolete: it admits the user to the network as a whole rather than to a specific resource. If an attacker gets inside this way, they are free to move laterally across the entire infrastructure. That mechanism is being replaced by the Zero Trust Network Access (ZTNA) architecture, which solves the problem at the root: it grants access to one required application and nothing else. Every other corporate service stays hidden from the outside world and invisible until authorisation is passed. The access decision itself is taken by a so-called trust broker at each new session, taking into account the user's identity and the state of their device.
In practice this approach has already proven itself in demanding industries. Global airlines, for example, now give thousands of their contractors worldwide secure access to critical GDS booking systems precisely through ZTNA. People work straight from a browser, with no VPN clients. The internal network is fully hidden, lateral movement by an attacker is ruled out, and every action is written to an audit log. For the banking sector this is an ideal pattern for working with external vendors.
Today, however, protecting human access is only half the job. Digitalisation brings new classes of risk in which the main actors are not people but autonomous AI agents. A modern AI agent is fundamentally different from the familiar chatbot: it can set its own sub-tasks, call tools, make decisions and act autonomously inside the infrastructure. In the financial sector such solutions are already used to automate the work of SOC analysts, anti-fraud systems and complex customer service scenarios. The catch is that every one of these agents needs direct access to the bank's databases and internal systems.
.jpg&w=3840&q=75)
The scale of this new reality deserves attention: the number of autonomous agents is expected to grow by 85% over the coming year. Machine identities in a typical organisation already outnumber employees by 80 to 1. Granting AI agents broad network access and standing privileges can lead to large-scale incidents, because machines act at millisecond speed and replicate any mistake instantly. Specific threats appear as well: prompt injection lets attackers use hidden instructions inside data to make an AI carry out malicious commands. Abuse of legitimate tools, theft of an agent's tokens and its standing privileges together create an enormous blast radius in the event of any compromise.
The answer lies in the same direction — the core principles of Zero Trust must be extended to AI agents as full-fledged subjects of the network. Every AI should have its own verifiable identity, firmly tied to a human owner. Instead of standing privileges, short-lived JIT tokens issued strictly for a specific task should be used (the zero standing privileges concept). Beyond that, a single MCP gateway must strictly limit the set of tools available to an agent and filter its input. Every API call and every request an AI makes to data should be logged continuously for audit and control.
Moving to such a layered architecture calls for a clear sequence. A bank's roadmap starts with a full inventory of every subject on the network: people, machines and AI agents. Next comes strict authentication, including phishing-resistant MFA. The step after that is replacing the VPN with ZTNA for targeted access to specific applications. The final stages cover microsegmentation, setting up guardrails for agents and launching continuous monitoring of their actions.
Managing autonomous AI subjects safely and protecting data is only possible today through a zero trust architecture. Strict identity verification, minimal privileges and full traceability of actions are the foundation that lets the financial sector adopt innovation without widening the surface for cyberattacks.
For its significant contribution to organising and running the CYBERFINANCE-2026 cyber exercises, Green Light received a letter of appreciation from the National Bank of the Kyrgyz Republic.