microsegment.io

segment all the things

Backup Infrastructure Needs Its Own Containment Boundary

A recovery copy is not resilient when production identities and network paths can still reach it

Ransomware operators target backup systems because destroying recovery increases leverage. This article explains how to isolate backup infrastructure, separate its identity plane, constrain management paths, and test recovery as a Zero Trust boundary.

AI Data Pipelines Need Containment

When untrusted data can execute code, the processing worker becomes an attack bridge

The July 2026 Hugging Face incident shows how a malicious dataset can become code execution, credential theft, and cross-cluster lateral movement. The answer is not only safer parsing. It is a smaller blast radius by design.

Your Identity Provider Needs a Containment Boundary

When the signing key is the credential, MFA is no longer the control

Mandiant's new AD FS research shows why federation servers belong inside a Tier 0 containment boundary, with tightly governed management paths, explicit dependencies, and an incident plan built around signing-key compromise.

The ATT&CK Segmentation Layer Is Now Updated to v19.1

The mapping stayed stable. The lesson did not get smaller.

The microsegment.io MITRE ATT&CK Network Segmentation Navigator layer has been refreshed to ATT&CK v19.1. The mappings stayed stable, and that stability says something useful about reachability, lateral movement, and containment.

What Good L3/L4 Policy Can Actually Do

A 2026 reassessment of MITRE ATT&CK, network segmentation, and practical microsegmentation

MITRE ATT&CK maps network segmentation to dozens of adversary techniques. This article reassesses what disciplined L3/L4 policy and microsegmentation can realistically do, where they help most, and where they stop.