Skip to main content
Oyoon Altaqnya

Micro-Segmentation

Fine-grained rules between servers and applications that stop an intruder moving from one compromised system to the next.

NIST CSF 2.0 functions
Protect
Relevant for
  • Banking and financial services
  • Telecommunications
  • Government and public sector
  • Oil and gas

Overview

Once inside, attackers move from server to server looking for data and administrator rights. In most data centers, a compromised machine can reach almost everything else.

We help you map how your applications really communicate and allow only the connections they need, so one intrusion stays small.

What you get

  • Critical applications and data reachable only from the systems that need them
  • An intruder on one server contained, instead of free to move across the data center
  • A visual map of how applications talk to each other
  • Rules that follow workloads when they move

What we cover

  • Application dependency mapping
  • Segmentation policy by application, environment and data sensitivity
  • Enforcement at the host, hypervisor or network level
  • Protection of east-west traffic inside the data center and cloud
  • Policy testing before enforcement
  • Logging and alerting on blocked connections

How we work

  1. Map

    We discover how applications communicate and group workloads by function and sensitivity.

  2. Design

    We design policies, starting with your most critical applications, and choose where each is enforced.

  3. Test

    We run policies in monitor mode and review what would have been blocked.

  4. Enforce and hand over

    We enforce in stages, document the policy model and train your teams to change rules safely.

Deliverables

  • Application dependency map
  • Segmentation policy design
  • Deployed and tested enforcement
  • Documentation and administrator training

Questions buyers ask

Is micro-segmentation the same as network segmentation?

No. Network segmentation divides the network into zones, usually by VLAN and firewall. Micro-segmentation controls traffic between individual workloads inside a zone.

Will it disrupt running applications?

Not if introduced carefully. We learn real traffic first, test rules in monitor mode and enforce one application group at a time.

  • Next-Generation Firewall (NGFW)

    Next-generation firewalls that control traffic by application, user and content, with a clean, documented rule base.

    NIST CSF function: Protect
  • Network Access Control (NAC)

    Control which devices and users may connect to your wired, wireless and remote networks, and place each one in the right network segment automatically.

    NIST CSF function: Protect
  • Network Detection & Response (NDR)

    Visibility into network traffic to detect lateral movement, command-and-control and data theft that endpoint tools cannot see.

    NIST CSF function: Detect