Pictured above: Another one of my totally organic, AI-free, hand-drawn “back of a literal envelope” diagrams showing the “limit the blast radius” benefits of network segmentation and microsegmentation.
Jack Poller, NetFoundry’s VP Product Marketing, kicked off a six-part microsegmentation series with the gap that nobody in the space likes to say out loud.
An Omdia survey of 352 security decision-makers found that:
- 99% of organizations are implementing or planning microsegmentation, and
- only 9% had protected more than 80% of their critical systems.
Half of them had been through a lateral-movement attack in the previous year, which is the exact thing microsegmentation is supposed to stop.
Here’s the article: The Microsegmentation Trap: Why 99% Are Planning It and Only 9% Protect Their Critical Systems.
Jack argues that the conventional playbook is the problem: Discover every flow, model the policy for the whole environment, simulate, then enforce. Each phase gates the next, and phase one never finishes because reality collides with your best laid plans:
- Applications talk to more things than anyone documented and
- dependencies shift while you’re charting them.
In the end, your initiative languishes in discovery for quarters and the crown jewels stay exactly as exposed as they were on day one.
The proposed fix? Turn the order upside down! Protect the single most critical asset first, one workload at a time, starting now.
Of course, this approach works only if enforcement stops depending on network location. As long as policy is based on IP ranges and zones, you’re back to needing the full topology before you can trust a rule. If you base policy on cryptographic identity, you can wrap one asset in tight policy today without having mapped what’s around it.
Once again, Jack’s article is here: The Microsegmentation Trap: Why 99% Are Planning It and Only 9% Protect Their Critical Systems.