Microsegmentation is a security approach that controls traffic between individual servers, virtual machines, containers or applications, rather than only between broad network zones. Each workload gets rules describing which other systems it may talk to and on which ports, and everything else is blocked. If an attacker compromises one system, they find far fewer paths to the rest of the environment. It is most common in data centers and cloud environments, and is usually enforced by software rather than by the physical network.
At a glance
- Microsegmentation sets allow rules per workload or application, not only per network zone.
- It is typically enforced by host agents, the virtualization platform, cloud security groups or internal firewalls.
- Its main value is limiting lateral movement after an initial compromise.
- Mapping real traffic flows first is essential, or rules will break applications.
- It is a practical way to apply zero trust principles inside the data center and cloud.
What problem it solves
Traditional segmentation puts a firewall between zones, such as users and servers, but servers inside the same zone can often talk to each other freely. Many attacks exploit exactly that. An attacker who compromises one web server or one file server can scan, reach and attack the database servers, domain controllers and backup systems next to it. Ransomware operators commonly spend time moving laterally like this before they encrypt.
Microsegmentation closes those internal paths. A web server might be allowed to reach only its application server, which can reach only its database, while nothing except backup software can reach the backup system. With host- or label-based enforcement, the same rules can follow workloads as they move between hosts or into the cloud. It also helps contain the impact of a compromised administrator account or a vulnerable system that can’t be patched straight away.
How it works
Discovery. Tools observe traffic between workloads over a period, often weeks, to map which systems genuinely talk to each other. Many products display this as a map of applications and their dependencies.
Policy design. Rules are written around workloads and labels such as application, environment and role, rather than IP addresses. For example, production finance application servers may talk to the finance database on one port, and nothing else.
Enforcement. Common approaches include:
- Host-based agents that program the operating system’s own firewall on each server.
- Virtualization or cloud platform controls, such as distributed firewalls in the hypervisor or cloud security groups.
- Network-based enforcement using network firewalls or switching features inside the data center, which suits environments where agents can’t be installed.
Rollout. Rules usually start in monitor-only mode, logging what would be blocked. Teams then enforce them in stages, starting with the most critical systems.
Ongoing management. As applications change, rules need updating. Good tools flag traffic that violates policy, which also provides a useful detection signal.
Microsegmentation applies the zero trust security idea that nothing should be trusted just because of where it sits on the network.
When it matters for buyers
- After a ransomware incident or near miss. Lateral movement is often what turns one infected server into a company-wide outage.
- When protecting crown-jewel systems. Finance applications, customer databases, backups and identity systems are common starting points.
- When building or refreshing a data center or private cloud. It’s easier to design microsegmentation in than to retrofit it.
- When auditors or regulators ask about isolating sensitive data. It can help demonstrate that regulated systems are separated, subject to your assessor’s view.
- When your environment spans on-premises and cloud. Workload-based rules can follow applications across both.
Questions to ask vendors
- How do you discover traffic flows, and how long does discovery take before we can write rules?
- Is enforcement agent-based, platform-based or network-based, and which operating systems and platforms are supported?
- How do you protect systems where we can’t install an agent?
- Can we run policies in monitor-only mode, and how do we roll back a rule that breaks something?
- How do policies follow workloads that move between hosts or into the cloud?
- What is the performance impact on servers, and what happens if the management console is unavailable?
- How is the product licensed: per workload, per host or another way?
How it differs from network segmentation
Network segmentation divides a network into zones, often built with virtual local area networks (VLANs) and subnets, and controls traffic between those zones, usually with a firewall at each boundary. Microsegmentation goes further, controlling traffic between individual workloads, including those inside the same zone. Segmentation is generally the first step and remains useful on its own; microsegmentation adds finer control where the risk justifies the extra design and maintenance effort, most often around servers in data centers and cloud environments.
