What Is Microsegmentation?

Also called: Micro-segmentation

Related problems: Once an attacker is on one server, they can reach all the others; Firewall rules between network zones are too coarse to protect critical applications; Ransomware spreading across our data center or cloud environment; Auditors asking how sensitive workloads are isolated

Microsegmentation is a security approach that controls traffic between individual servers, virtual machines, containers or applications, rather than only between broad network zones. Each workload gets rules describing which other systems it may talk to and on which ports, and everything else is blocked. If an attacker compromises one system, they find far fewer paths to the rest of the environment. It is most common in data centers and cloud environments, and is usually enforced by software rather than by the physical network.

At a glance

  • Microsegmentation sets allow rules per workload or application, not only per network zone.
  • It is typically enforced by host agents, the virtualization platform, cloud security groups or internal firewalls.
  • Its main value is limiting lateral movement after an initial compromise.
  • Mapping real traffic flows first is essential, or rules will break applications.
  • It is a practical way to apply zero trust principles inside the data center and cloud.

What problem it solves

Traditional segmentation puts a firewall between zones, such as users and servers, but servers inside the same zone can often talk to each other freely. Many attacks exploit exactly that. An attacker who compromises one web server or one file server can scan, reach and attack the database servers, domain controllers and backup systems next to it. Ransomware operators commonly spend time moving laterally like this before they encrypt.

Microsegmentation closes those internal paths. A web server might be allowed to reach only its application server, which can reach only its database, while nothing except backup software can reach the backup system. With host- or label-based enforcement, the same rules can follow workloads as they move between hosts or into the cloud. It also helps contain the impact of a compromised administrator account or a vulnerable system that can’t be patched straight away.

How it works

Discovery. Tools observe traffic between workloads over a period, often weeks, to map which systems genuinely talk to each other. Many products display this as a map of applications and their dependencies.

Policy design. Rules are written around workloads and labels such as application, environment and role, rather than IP addresses. For example, production finance application servers may talk to the finance database on one port, and nothing else.

Enforcement. Common approaches include:

  • Host-based agents that program the operating system’s own firewall on each server.
  • Virtualization or cloud platform controls, such as distributed firewalls in the hypervisor or cloud security groups.
  • Network-based enforcement using network firewalls or switching features inside the data center, which suits environments where agents can’t be installed.

Rollout. Rules usually start in monitor-only mode, logging what would be blocked. Teams then enforce them in stages, starting with the most critical systems.

Ongoing management. As applications change, rules need updating. Good tools flag traffic that violates policy, which also provides a useful detection signal.

Microsegmentation applies the zero trust security idea that nothing should be trusted just because of where it sits on the network.

When it matters for buyers

  • After a ransomware incident or near miss. Lateral movement is often what turns one infected server into a company-wide outage.
  • When protecting crown-jewel systems. Finance applications, customer databases, backups and identity systems are common starting points.
  • When building or refreshing a data center or private cloud. It’s easier to design microsegmentation in than to retrofit it.
  • When auditors or regulators ask about isolating sensitive data. It can help demonstrate that regulated systems are separated, subject to your assessor’s view.
  • When your environment spans on-premises and cloud. Workload-based rules can follow applications across both.

Questions to ask vendors

  • How do you discover traffic flows, and how long does discovery take before we can write rules?
  • Is enforcement agent-based, platform-based or network-based, and which operating systems and platforms are supported?
  • How do you protect systems where we can’t install an agent?
  • Can we run policies in monitor-only mode, and how do we roll back a rule that breaks something?
  • How do policies follow workloads that move between hosts or into the cloud?
  • What is the performance impact on servers, and what happens if the management console is unavailable?
  • How is the product licensed: per workload, per host or another way?

How it differs from network segmentation

Network segmentation divides a network into zones, often built with virtual local area networks (VLANs) and subnets, and controls traffic between those zones, usually with a firewall at each boundary. Microsegmentation goes further, controlling traffic between individual workloads, including those inside the same zone. Segmentation is generally the first step and remains useful on its own; microsegmentation adds finer control where the risk justifies the extra design and maintenance effort, most often around servers in data centers and cloud environments.

Frequently Asked Questions

Is microsegmentation the same as network segmentation?
It is a finer-grained form of it. Network segmentation divides a network into zones, such as users, servers and guests, and controls traffic between them. Microsegmentation controls traffic between individual workloads, so even servers in the same zone can only talk to each other when a rule allows it.
Do we need new hardware for microsegmentation?
Often not. Many approaches use software agents on servers, features of the virtualization platform or cloud security groups. Some designs use network firewalls inside the data center. Which approach fits depends on your environment and the tools you already own.
How does microsegmentation help against ransomware?
Ransomware operators typically move from one system to others before encrypting. If each server can only reach the systems it genuinely needs, that movement becomes harder and noisier, which can limit the damage and make detection more likely. It doesn't stop the initial compromise.
Is microsegmentation only for large enterprises?
No, though it is most common in larger data centers and cloud environments. Mid-sized companies often start with their most critical systems, such as finance applications, backups and domain controllers, rather than everything at once.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.