microsegment.io

segment all the things

mTLS Is Not A Containment Policy

A trusted workload identity still needs a narrow list of permitted destinations and operations

Mutual TLS authenticates service connections. Breach containment also needs explicit authorization, network boundaries, and tests using valid but unauthorized workload identities.

OT Integrator Access Needs An Expiry Date

Separate retained engineering knowledge from live access, then prove you can disconnect one supplier

The September 2026 FBI/CISA ICS integrator guidance raises two different containment problems: engineering data outside the plant and remote access into it. A practical microsegmentation pattern for supplier-specific access, project closure, and independent revocation.

The Platform Was Not Breached. The Delegated Key Was.

The BigCommerce Ribon incident shows why third-party SaaS identities need their own containment boundaries

Compromised credentials for the Ribon BigCommerce apps reportedly enabled customer-data access and storefront script injection across merchant environments. This article explains how to contain delegated SaaS identities with narrow scopes, separated permissions, independent revocation, and behavioral monitoring.

The Email Security Gateway Is Now An Attack Origin

CVE-2026-76461 turns one crafted message into a root-level containment problem

Cisco Secure Email Gateway CVE-2026-76461 is actively exploited and can provide root command execution through email parsing. This article explains how to contain the appliance across mail, management, egress, identity, and evidence paths.

Your Microsegmentation Policy Is Not Proven Until You Test The Deny

A clean rule set is not evidence that lateral movement paths are closed

Microsegmentation only reduces blast radius when denied paths are tested from real workloads. This article presents a practical method for validating policy enforcement, identity context, failure behavior, and containment over time.