By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: ElisityPublished September 30, 2025

TL;DR: Microsegmentation adoption remains between 5% and 20% of enterprises even as the category is forecast to grow from $8.2 billion in 2025 to more than $41 billion by 2034, according to Elisity and Gartner. The gap shows that lateral movement reduction is still a governance problem, not just a tooling choice.


At a glance

What this is: This buyer’s guide argues that microsegmentation is now a core lateral movement control, but enterprise adoption remains low even as the market expands and vendor approaches diversify.

Why it matters: For IAM, PAM, and security teams, the identity-based angle matters because microsegmentation increasingly intersects with workload access, privileged paths, and machine identity controls.

By the numbers:

👉 Read Elisity's microsegmentation vendor comparison and buyer's guide for 2026


Context

Microsegmentation is the practice of enforcing least-privilege communication between workloads, devices, and internal segments so that one compromised asset cannot move freely across the environment. In this article, the primary governance gap is not whether microsegmentation exists as a concept, but why adoption still trails the lateral movement risk it is meant to contain.

The identity angle is genuine because modern segmentation is increasingly tied to identity-based enforcement, workload access, privileged ports, and machine identity controls. That makes the topic relevant to IAM, PAM, and NHI programmes as much as to network teams, especially where service accounts, automation, and unmanaged devices intersect with east-west traffic.

The article is a vendor comparison, so its starting position is typical of a market guide: it frames a crowded category, compares deployment models, and then turns the decision back to environment fit rather than a single universal best practice.


Key questions

Q: How should critical infrastructure teams implement microsegmentation around OT systems?

A: Start by grouping assets by operational function and trust dependency, not by subnet convenience. Allow only the flows that are required for control, maintenance, and monitoring, then verify that a compromised corporate endpoint cannot reach critical OT assets. The goal is to reduce blast radius, not to create a paper architecture that still allows lateral movement.

Q: Why does microsegmentation matter so much for lateral movement risk?

A: Because most successful breaches become far more damaging after the first foothold. Microsegmentation limits east-west paths, so a compromised account or workload cannot freely pivot across the environment. That reduces the blast radius of initial access and gives incident responders a smaller, more containable security problem.

Q: What do security teams get wrong about microsegmentation?

A: They often treat it as a one-time network redesign instead of an iterative control that depends on current workload behaviour. If policies are not refreshed as applications change, segmentation becomes stale and leaves blind spots that attackers can exploit.

Q: Who should own microsegmentation when identity is part of the policy model?

A: Ownership should be shared across network, IAM, and security architecture teams because the policy now depends on identity sources as much as on enforcement points. Network teams can implement the control, but IAM and identity governance teams are needed to keep the identity data trustworthy and the access model consistent.


Technical breakdown

Agentless versus agent-based microsegmentation

Microsegmentation tools generally fall into two technical camps. Agent-based platforms install software on workloads and can inspect host activity, but they struggle where endpoints are unmanaged, fragile, or outside the team’s control. Agentless platforms enforce policy at the network edge or through inline infrastructure, which broadens coverage for OT, IoT, and mixed estates. The trade-off is visibility depth versus deployment reach, and that trade-off drives most real-world selection decisions.

Practical implication: inventory which assets can actually run an agent before you shortlist vendors.

Identity-based policy enforcement and east-west control

Identity-based segmentation ties policy to who or what the asset is, not just which subnet it lives in. In practice, that means the policy engine uses workload identity, device identity, or access context to decide whether east-west traffic should be allowed. This matters because lateral movement usually follows trusted internal paths, not obvious perimeter failures. When segmentation is identity-aware, it can reduce reliance on flat network zones and static allowlists.

Practical implication: align segmentation policy with workload and service identity rather than only with IP ranges.

Microsegmentation as a lateral movement control

Microsegmentation is fundamentally a blast-radius control. If an attacker reaches one host through stolen credentials, phishing, or exposed remote access, segmentation determines whether that foothold becomes a broad internal compromise or a contained incident. The control does not prevent initial compromise, but it can stop credential reuse, privilege chaining, and east-west traversal. That is why it sits alongside IAM, PAM, and NHI governance in mature programmes.

Practical implication: treat segmentation as a containment layer and map it to known lateral movement paths.


Threat narrative

Attacker objective: The attacker’s objective is to move laterally across internal assets and turn one compromised endpoint or workload into a larger enterprise breach.

  1. Entry occurs when an attacker gains a foothold on one internal asset through a stolen credential, exposed service, or compromised host.
  2. Escalation follows as the attacker reuses trusted internal paths to reach adjacent workloads, service accounts, or admin surfaces.
  3. Impact occurs when the attacker expands from the initial host into broader east-west movement, increasing the scope of data theft or disruption.

NHI Mgmt Group analysis

Microsegmentation is now a governance control, not just a network design choice. Once internal movement becomes the primary attacker objective, segmentation sits in the same decision set as IAM, PAM, and machine identity governance. The buyer question is no longer only which traffic can be blocked, but which identities and trust paths can be constrained when credentials are compromised. Practitioners should treat segmentation as part of access governance, not as an isolated network project.

Identity-based enforcement is the most important shift in this category. The market is moving away from purely IP-centric control toward policy that follows workloads, devices, and privileged paths. That matters because enterprise environments now mix human users, service accounts, automation, and unmanaged devices in ways that static network zoning cannot express cleanly. The result is a stronger case for identity-aware policy design, especially where NHI sprawl creates hidden east-west reachability.

Blast-radius segmentation: this is the specific problem the category is trying to solve, and it is the right named concept for practitioners to track. The gap is not only flat networks, but the persistence of internal trust after initial compromise. In that sense, microsegmentation is a containment discipline for environments where zero trust has not yet reached the east-west layer. Teams should evaluate tools by how well they reduce reachable trust paths, not by feature count alone.

Agentless coverage matters most where the estate is least controllable. Mixed IT, OT, IoT, and industrial environments often contain assets that cannot accept a host agent without operational risk. That makes the deployment model itself a governance decision, because the wrong model leaves the most exposed assets unsegmented. Practitioners should re-evaluate their coverage assumptions wherever unmanaged or safety-critical devices are part of the internal attack surface.

Microsegmentation adoption is still lagging because deployment friction is a programme problem. The article’s market numbers show strong demand, but the real bottleneck is not awareness. It is the mismatch between security ambition, operational complexity, and asset diversity. That means microsegmentation programmes succeed when they are scoped around measurable containment goals and integrated with identity controls, not when they are treated as a one-time network redesign.

What this signals

Microsegmentation programmes are increasingly being evaluated as containment layers for identity-driven lateral movement, not just as network hygiene. That shifts the implementation question toward coverage, exception management, and how the control interacts with service accounts, privileged paths, and internal trust relationships. For identity programmes, the lesson is that east-west exposure is now part of access governance, not a separate conversation.

Blast-radius segmentation: the concept captures where the market is heading. Teams need controls that reduce reachable paths after a foothold, especially where human identities, NHI sprawl, and unmanaged devices coexist. The practical next step is to align segmentation policy with identity context and validate it against the paths an attacker would actually use.

Practitioners should also expect buyers to ask for evidence of containment rather than broad feature claims. That makes testability, not just architecture, a procurement criterion. Mapping those tests to frameworks such as NIST Cybersecurity Framework 2.0 and the MITRE ATT&CK Enterprise Matrix helps translate segmentation into measurable security outcomes.


For practitioners

  • Map segmentation to trusted east-west paths Document which internal paths currently allow an attacker to move from one workload, admin port, or service account to another. Prioritise the routes that carry the highest privilege or the most sensitive data, then block or restrict them first. The point is to reduce blast radius, not to segment everything at once.
  • Separate agent-feasible from agentless-required assets Build your rollout plan around device reality, not vendor architecture. Tag workloads, unmanaged devices, OT assets, and IoT endpoints that cannot support an agent, then require an enforcement model that still covers them. This prevents the common failure where the best-protected assets become the only ones in scope.
  • Tie microsegmentation policy to identity signals Use workload identity, device identity, and privileged access context in the policy design where the platform supports it. That gives the segmentation layer a better chance of distinguishing legitimate service traffic from compromised internal activity. This is especially useful when service accounts and automation accounts drive east-west communication.
  • Test containment with lateral movement scenarios Run validation exercises that simulate an internal foothold and then try to traverse to adjacent systems, admin interfaces, and sensitive workloads. Measure whether the policy stops movement before it reaches high-value targets, and record where exceptions still create unexpected reachability. Use those results to refine the policy model.

Key takeaways

  • Microsegmentation is best understood as a containment control for internal lateral movement, not a standalone network project.
  • The adoption gap shows that the market still struggles with coverage, device diversity, and policy lifecycle ownership.
  • Identity-aware enforcement is becoming central because workload identity, privileged access, and NHI governance now shape east-west risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0006 , Credential Access; TA0008 , Lateral MovementThe article centers on containment of internal movement after initial access.
NIST CSF 2.0PR.AC-4Segmentation is an access-control control with direct governance value.
NIST SP 800-53 Rev 5AC-4AC-4 governs information flow enforcement, which is the core of segmentation.
CIS Controls v8CIS-12 , Network Infrastructure ManagementNetwork boundary and internal path management are central to the buyer's guide.
NIST Zero Trust (SP 800-207)The article's identity-based enforcement aligns with zero trust segmentation principles.

Map east-west exposure to credential access and lateral movement tactics, then test whether segmentation breaks the chain.


Key terms

  • Microsegmentation: A network control approach that divides environments into small security zones with explicit rules between them. Its purpose is to limit lateral movement and reduce blast radius when an identity, workload, or device is compromised.
  • East-west traffic: East-west traffic is communication that moves between systems inside an environment rather than entering or leaving it. In microsegmentation programmes, it is the traffic most likely to expose hidden trust assumptions and is therefore the main target for workload-level policy.
  • Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
  • Identity-linked policy enforcement: Identity-linked policy enforcement ties access decisions to the user, device, and approved context rather than relying on awareness training alone. It is the practical mechanism that helps organisations distinguish sanctioned AI use from shadow AI behaviour.

What's in the full article

Elisity's full guide covers the operational detail this post intentionally leaves for the source:

  • Side-by-side vendor comparison table with deployment model, agent requirements, OT support, cloud support, and differentiators.
  • Detailed profile notes for each vendor, including best-fit environments and deployment considerations.
  • Analyst standing and recognition across Forrester, Gartner, GigaOm, and Constellation Research.
  • Buyer scorecard criteria and practical evaluation questions for shortlisting microsegmentation tools.

👉 Elisity's full guide includes the comparison table, analyst context, and vendor-by-vendor fit notes.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, workload identity, and secrets management. It is designed for practitioners who need to connect identity controls to broader security architecture and operational governance.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 22, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org