Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Microsegmentation and lateral movement risk: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: Microsegmentation adoption remains between 5% and 20% of enterprises even as the category is forecast to grow from $8.2 billion in 2025 to more than $41 billion by 2034, according to Elisity and Gartner. The gap shows that lateral movement reduction is still a governance problem, not just a tooling choice.

NHIMG editorial — based on content published by Elisity: Top Microsegmentation Solutions for 2026: Vendor Comparison and Buyer’s Guide

By the numbers:

  • CrowdStrike’s 2026 Global Threat Report says eCrime breakout time averages 29 minutes.

Questions worth separating out

Q: How should critical infrastructure teams implement microsegmentation around OT systems?

A: Start by grouping assets by operational function and trust dependency, not by subnet convenience.

Q: Why does microsegmentation matter so much for lateral movement risk?

A: Because most successful breaches become far more damaging after the first foothold.

Q: What do security teams get wrong about microsegmentation?

A: They often treat it as a one-time network redesign instead of an iterative control that depends on current workload behaviour.

Practitioner guidance

  • Map segmentation to trusted east-west paths Document which internal paths currently allow an attacker to move from one workload, admin port, or service account to another.
  • Separate agent-feasible from agentless-required assets Build your rollout plan around device reality, not vendor architecture.
  • Tie microsegmentation policy to identity signals Use workload identity, device identity, and privileged access context in the policy design where the platform supports it.

What's in the full article

Elisity's full guide covers the operational detail this post intentionally leaves for the source:

  • Side-by-side vendor comparison table with deployment model, agent requirements, OT support, cloud support, and differentiators.
  • Detailed profile notes for each vendor, including best-fit environments and deployment considerations.
  • Analyst standing and recognition across Forrester, Gartner, GigaOm, and Constellation Research.
  • Buyer scorecard criteria and practical evaluation questions for shortlisting microsegmentation tools.

👉 Read Elisity's microsegmentation vendor comparison and buyer's guide for 2026 →

Microsegmentation and lateral movement risk: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

Microsegmentation is now a governance control, not just a network design choice. Once internal movement becomes the primary attacker objective, segmentation sits in the same decision set as IAM, PAM, and machine identity governance. The buyer question is no longer only which traffic can be blocked, but which identities and trust paths can be constrained when credentials are compromised. Practitioners should treat segmentation as part of access governance, not as an isolated network project.

A question worth separating out:

Q: Who should own microsegmentation when identity is part of the policy model?

A: Ownership should be shared across network, IAM, and security architecture teams because the policy now depends on identity sources as much as on enforcement points. Network teams can implement the control, but IAM and identity governance teams are needed to keep the identity data trustworthy and the access model consistent.

👉 Read our full editorial: Microsegmentation still lags adoption despite lateral movement risk



   
ReplyQuote
Share: