microsegment.io

segment all the things

What Good L3/L4 Policy Can Actually Do

A 2026 reassessment of MITRE ATT&CK, network segmentation, and practical microsegmentation

MITRE ATT&CK maps network segmentation to dozens of adversary techniques. This article reassesses what disciplined L3/L4 policy and microsegmentation can realistically do, where they help most, and where they stop.

Voice Infrastructure Needs Containment, Too

Cisco Unified CM exploitation is a reminder that communication platforms are high-trust infrastructure

Cisco Unified CM CVE-2026-20230 shows why voice and collaboration systems need microsegmentation, management-plane isolation, and clear blast-radius boundaries before compromise turns into lateral movement.

Non-Human Identities Need Containment, Not Just Rotation

Service accounts, API keys, OAuth apps, and agents are now lateral movement infrastructure

Non-human identities are becoming one of the most important trust paths in modern environments. This article explains why service accounts, API keys, OAuth apps, and AI agents need microsegmentation and blast-radius control, not just secrets hygiene.

Microsegmentation in 2026: The Control That Turns Breach Assumption Into Architecture

Why lateral movement, cloud sprawl, identity drift, and AI agents are making containment a board-level priority

A 2026 trend view on microsegmentation: vulnerability exploitation, ransomware, identity drift, cloud complexity, and AI agents all point to the same need - smaller blast radius by design.

8 Microsegmentation pitfalls to avoid

I read a nice article by Ericka Chickowski on Darkreading the other day. The article gives some great guidance on what to do and not to do when starting your segmentation journey. Here are some comments. The practice of microsegmentation takes the principles of least privilege to their logical conclusion by atomizing the isolating techniques of network segmentation. Security architects use microsegmentation to create security boundaries that can extend all the way into individual workloads by controlling East-West, or server-to-server, traffic flows between applications. The bulkheads put up through microsegmentation make it possible to better limit lateral movement of attackers, even in a cloudy world with no perimeter.