Network & Perimeter
Microsegmentation MICROSEG
An approach that restricts traffic between servers and workloads on a per-application basis. Even if one server is compromised, it stops the attacker from spreading to other servers (lateral movement).
When you need it
- Many of your servers sit on a flat (unsegmented) network
- Ransomware spreading across your entire data center is your biggest fear
- You want to shrink your PCI DSS scope (cardholder data environment)
When you do not need it
- With a small number of servers, VLAN separation and firewall rules are enough.
- You can't segment without first seeing the traffic; don't buy a product without an application dependency map.
Via agents on servers or through hypervisor/cloud security groups. First map traffic in monitoring mode, then restrict, starting with critical applications.



