TL;DR: Network segmentation reduces lateral movement by breaking flat networks into smaller trust zones, but poor segmentation, third-party overreach, and weak auditability still leave organisations exposed, according to StrongDM and IBM. The security case now depends on making legitimate access easier than illegitimate movement, not just adding more network boundaries.
At a glance
What this is: This is a network segmentation best-practices article that argues segmentation only helps when access paths, third parties, monitoring, and privilege boundaries are designed together.
Why it matters: For IAM and NHI practitioners, the article matters because segmentation without least privilege and auditable access can leave service accounts, vendors, and users able to move farther than intended.
By the numbers:
- Data breach costs rose from $3.86 million to $4.24 million USD, according to IBM research cited by StrongDM.
Context
Network segmentation is the practice of dividing a network into smaller contained zones so a compromise in one area does not automatically expose everything else. In identity terms, the control is only as strong as the access model that sits on top of it, because users, vendors, services, and workloads still need governed paths into each zone.
The article frames segmentation as a security and governance problem, not just a network design choice. The practical issue is that flat connectivity, overbroad third-party reach, and weak audit trails turn a segmented environment into little more than a visual diagram unless access is tightly scoped and monitored.
For IAM and NHI teams, the question is how segmentation interacts with least privilege, role-based access, and forensic visibility. When those controls are weak, a network boundary does not stop misuse of legitimate access, it only relocates it deeper into the environment.
Key questions
A: Start by mapping who needs access to which data and services, then design segments around those access needs rather than around organizational charts. Keep legitimate traffic paths simpler than attacker paths, isolate third-party access into restricted portals, and review the design regularly. Good segmentation limits lateral movement, reduces blast radius, and makes containment easier when an intrusion succeeds.
Q: Why do overbroad third-party permissions make segmentation less effective?
A: Because segmentation only contains risk if external access is tightly bounded. When a vendor can move through multiple internal zones from one entry point, the organisation has expanded the trust boundary instead of reducing it, and lateral movement becomes easier to hide.
Technical breakdown
How segmentation limits lateral movement in flat networks
Network segmentation works by splitting a broad trust domain into smaller zones, each with its own permitted flows. In a flat network, once an attacker enters, internal paths often let them discover, query, and reach more systems with minimal friction. Segmentation interrupts that movement by forcing traffic through controlled chokepoints such as firewalls, gateways, or software-defined policy layers. The security value comes from narrowing the blast radius of any single foothold and creating more observable trust boundaries between systems. That only holds when the boundaries are enforced consistently across users, vendors, services, and administrative paths.
Practical implication: treat each segment as a governed access zone, not just a routing boundary.
Why least privilege and third-party access are the real control plane
The article’s core governance point is that segmentation fails when access is broader than the task. Least privilege means hosts, users, services, and vendors should only reach the systems needed for their immediate work, not the wider network around them. Third-party access is especially sensitive because remote vendor entry can become a standing pathway into multiple zones if it is not isolated and tightly scoped. For identity teams, this is an NHI and access-governance problem as much as a network problem, because service accounts, remote sessions, and delegated access all expand the effective trust perimeter.
Practical implication: scope third-party and machine access to the smallest reachable zone and review it as part of lifecycle governance.
Why audit trails and topology visibility determine whether segmentation works
Segmentation only improves security if teams can see who accessed what, from where, and through which path. The article points out that traditional access layers can leave weak forensic detail, showing only that a session happened rather than the specific queries or commands inside it. That is a serious limitation when a breach moves through legitimate credentials, because the organisation needs to reconstruct movement inside the network, not just confirm entry. Visualisation is therefore not cosmetic. It is the control that lets teams map trust boundaries, spot over-segmentation, and identify where access rules no longer match the current environment.
Practical implication: ensure every segmented path has enough telemetry to support forensics and policy review.
NHI Mgmt Group analysis
Network segmentation is an access-governance problem before it is a network design problem. The article correctly treats segmentation as a way to contain movement, but the real failure mode is overly broad legitimacy inside the environment. When access paths are not mapped to actual need, segmentation becomes cosmetic and lateral movement remains possible through approved channels. Practitioners should read segmentation as a governance layer over identity and transport, not as a substitute for them.
Third-party access turns segmentation into an NHI control issue as soon as vendors touch internal zones. The article’s strongest point is that remote access is often where the trust model breaks first. If a third party can cross multiple segments with one overextended path, the organisation has not segmented the network so much as redistributed risk across zones. The implication is that vendor access boundaries must be lifecycle-governed with the same discipline applied to internal privilege.
Auditability is the difference between containment and blind containment. Segmentation that cannot show who issued a command, what system was reached, and how traffic moved cannot support credible investigation or policy correction. That matters for both human and non-human identities, because the same lack of visibility hides misuse by admins, service accounts, and delegated access channels. The practitioner conclusion is simple: if you cannot reconstruct access, you have not really governed it.
Legitimate-path design is the named concept that matters most here. The article’s best insight is that defenders should make authorised access easier than unauthorised movement. That shifts security design away from purely defensive barriers and toward controlled, observable routes into each zone. For identity programmes, this means the access architecture must favour explicit pathways, narrow entitlements, and verifiable session trails over convenience-driven reach.
Over-segmentation can degrade governance as effectively as no segmentation at all. Too many zones create too many policy combinations, which increases operational complexity and makes access drift harder to manage. That is a lifecycle problem as much as a topology problem, because every added zone expands the review surface for entitlement, monitoring, and change control. Practitioners should optimise for governable segmentation, not maximal partition count.
From our research library:
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs.
- Read next: Zero Trust Identity Guide
What this signals
Legitimate-path design: The control question is no longer whether a network is segmented, but whether approved access routes are more visible and more constrained than the paths an attacker would prefer. That is where least privilege becomes operational rather than rhetorical.
Segmentation programmes that lack command-level audit trails will struggle to prove containment, especially when vendors or service accounts are involved. The practical test is whether the team can reconstruct movement inside each zone without relying on a vague session record.
For identity leaders, the next step is to align segmentation with access governance, not only with perimeter design. That means every zone should have an owner, a purpose, and a reviewable access model that can survive organisational change.
For practitioners
- Map access to segment ownership Define which users, services, and third parties are allowed into each zone and document the business reason for every path. Use that map to remove broad network reach that is not tied to an explicit operational need.
- Isolate third-party access portals Create dedicated access paths for vendors and contractors so their sessions are confined to only the systems they support. Avoid letting external access traverse the same broad pathways used by internal administrators or service accounts.
- Instrument segmented paths with forensic logging Capture enough session detail to reconstruct commands, queries, and accessed targets inside each zone. Session-only records are insufficient when the goal is to investigate movement through approved paths.
- Review segmentation for governability, not just isolation Check whether the number of zones, policies, and exceptions is still manageable as the environment changes. If policy upkeep is outpacing the team’s ability to audit it, the design is too complex to sustain.
Key takeaways
- Network segmentation only reduces exposure when it is paired with disciplined access governance and clear boundaries for users, vendors, and services.
- The strongest evidence in the article is that breach costs remain high and that poor visibility, third-party overreach, and over-segmentation undermine the promised benefits.
- Practitioners should focus on governable zones, narrow entitlements, and forensic visibility rather than treating segmentation as a standalone network control.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centers on limiting access scope for services and third parties. |
| NHI-10 — Human Use of NHI | The article highlights vendor and staff access paths that should not be broader than their tasks. | |
| Recommendation — Apply NHI-05 to reduce internal reach and align each identity to the smallest necessary segment. Use NHI-10 to separate human and non-human access paths and remove shared trust boundaries. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Least privilege and zoned access are the article's core governance themes. |
| Recommendation — Review entitlements so each segment only exposes the permissions required for its approved use cases. | ||
| CIS Controls v8 | CIS-5 — Account Management | Third-party and internal access must be managed as part of the account lifecycle. |
| Recommendation — Track, review, and remove accounts that no longer need access to segmented zones. | ||
| MITRE ATT&CK | TA0008 — Lateral Movement | The article is fundamentally about containing attacker movement between internal zones. |
| Recommendation — Map segmentation gaps to lateral movement paths and harden the routes attackers could use after initial access. | ||
Key terms
- Network Segmentation: Network segmentation divides traffic and resources into controlled zones so access can be restricted between groups, systems, or applications. In remote access design, segmentation limits what a connected user or workload can reach after authentication, which reduces lateral movement and shrinks blast radius.
- Least Privilege: A security principle requiring that every identity, human or non-human, is granted only the minimum permissions necessary to perform its function. Least privilege is the single most effective control for reducing NHI blast radius.
- Third-Party Access: Third-party access is access granted to vendors, contractors, or support partners who are not direct employees of the organisation. It is higher risk than internal access because accountability, device assurance, and access duration are harder to control, so it usually requires tighter time limits and stronger auditability.
- Lateral Movement: A post-compromise technique where an attacker uses a compromised NHI to move through a network, accessing additional systems and escalating impact without triggering detection.
Deepen your knowledge
NHI governance, identity lifecycle management, and workload identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org