Start by mapping application and workload communication so teams can see where critical systems are exposed, then apply granular segmentation to restrict only the traffic that is necessary and wanted. This approach helps organisations prove control over lateral movement, reduce blast radius, and align security operations with resilience and continuity requirements in regulated environments.
Why Zero Trust Segmentation Fits NIS2 and DORA
zero trust Segmentation gives organisations a practical way to translate compliance intent into enforceable traffic boundaries. NIS2 and DORA both expect stronger control over ICT exposure, resilience, and operational continuity, so segmentation becomes more than a network design choice: it is evidence that critical services are deliberately isolated, monitored, and constrained.
For regulated environments, that matters because uncontrolled east-west movement turns a local compromise into a wider operational event. Segmentation helps teams show that critical systems are not broadly reachable by default, which supports both governance expectations and incident containment.
How Segmentation Supports Control, Resilience, and Auditability
The most useful starting point is communication mapping. You need to know which applications, services, and workloads truly depend on one another before you can define acceptable traffic paths. Once that dependency picture is clear, segmentation can be applied in a targeted way so that only necessary flows remain open.
This approach supports resilience because it reduces blast radius if one workload, application, or privileged path is compromised. It also supports auditability because the organisation can explain why each permitted connection exists and how the policy limits unintended lateral movement.
Segmentation is strongest when it is paired with operational ownership. Security teams may design the policy, but application and platform owners need to confirm which flows are business-essential, which are legacy exceptions, and which should be retired entirely.
Where Zero Trust Segmentation Matters Most in Practice
The biggest gains usually come from protecting critical business services, high-value administrative paths, and environments where a flat network would otherwise let one compromise spread quickly. That includes production workloads, sensitive data processing zones, and third-party connected services that introduce additional trust edges.
It also matters during change. As systems evolve, new integrations often get added faster than old ones are removed. A segmentation model that is reviewed against actual traffic patterns helps prevent drift, while keeping the policy aligned with current operational reality rather than inherited architecture.
For NIS2 and DORA, the practical value is not just isolation. It is the combination of isolation, demonstrable control, and repeatable review. That is what allows organisations to defend resilience claims during assurance, incident review, or supervisory scrutiny.
Risk and Threat Considerations
Without segmentation, a single compromised host or account can become a bridge into other systems, especially when legacy trust paths and broad internal connectivity were never removed. That creates a direct exposure to lateral movement, larger incident scope, and harder containment during a security event.
Failure mechanism: Overly permissive internal connectivity allows attackers or malfunctioning services to move beyond the initial entry point, reaching systems that were never intended to be broadly reachable.
Impact: The result can be wider operational disruption, more difficult recovery, and weaker evidence that critical services are protected by proportionate controls.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022, DORA and NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | SC-7 — Boundary Protection | Segmentation directly implements internal boundary control for critical system communication. |
| AC-4 — Information Flow Enforcement | Zero Trust Segmentation restricts which communications are permitted between systems. | |
| Recommendation — Define and enforce internal boundaries so only approved traffic can reach critical workloads. Enforce policy-based information flow rules for application and workload traffic. | ||
| NIST CSF 2.0 | PR.AA-05 — Least Privilege | Segmentation supports least-privilege connectivity by limiting what systems can talk to each other. |
| PR.IR-01 — Networks are Managed to Protect Assets | Network segmentation is a direct way to manage internal network exposure and containment. | |
| Recommendation — Limit system-to-system reachability to the minimum necessary for business function. Use segmentation to reduce exposure and contain compromise paths across the environment. | ||
| ISO/IEC 27001:2022 | A.8.20 — Networks security | Segmentation is a core network security control used to restrict and separate traffic. |
| Recommendation — Apply network security controls that separate critical systems and restrict unnecessary connectivity. | ||
| DORA | ICT third-party risk management — ICT third-party risk management | Segmentation helps constrain risk from interconnected ICT services and suppliers. |
| Recommendation — Segment third-party-connected systems to reduce dependency risk and contain failures. | ||
| NIS2 | Cybersecurity risk-management measures — Cybersecurity risk-management measures | Segmentation is one of the operational measures used to reduce exposure and improve resilience. |
| Recommendation — Use segmentation as a risk-management measure to reduce exposure and support resilience. | ||
Practitioner Guidance
What to prioritise: Start with the highest-value applications and the traffic paths that would create the greatest blast radius if abused. That is usually more effective than trying to segment everything at once.
What to verify: Confirm that every allowed flow has an owner, a business justification, and a review point. If a path cannot be explained clearly, it is usually a candidate for tightening or removal.
What good looks like: Critical systems have only the minimum necessary east-west paths, exceptions are time-bound and documented, and containment can be shown through policy rather than assumed from the network perimeter.
Practitioner takeaway: Treat segmentation as a control over operational reach, not just a routing exercise, because compliance confidence comes from being able to prove that critical communication is intentional, limited, and reviewable.
Related resources from NHI Mgmt Group
- How should organisations use identity governance and administration to support Zero Trust without creating administrative drag?
- How should federal agencies use network segmentation to support a Zero Trust architecture?
- How should organisations use access reviews to support PCI DSS compliance?
- How should organisations use a Zero Trust gap analysis in practice?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org