microsegment.io

segment all the things

OT Segmentation Must Survive Edge Compromise

The Polish energy-sector attack showed why VLANs are not containment when one administrator can reach every control subnet

CERT Polska's investigation of the December 2025 energy-sector attack shows how compromised VPN and identity control paths can flatten OT segmentation. This article turns the incident into a practical containment design for remote sites, SCADA, RTUs, HMIs, and safety-critical systems.

Microsegmentation Fails Quietly When Policy Drifts

The first policy is only a snapshot. Containment depends on keeping it aligned with the environment.

Microsegmentation policy can decay as applications, workloads, identities, and exceptions change. This article explains how to detect policy drift, govern exceptions, and continuously prove that lateral movement paths remain closed.

Backup Infrastructure Needs Its Own Containment Boundary

A recovery copy is not resilient when production identities and network paths can still reach it

Ransomware operators target backup systems because destroying recovery increases leverage. This article explains how to isolate backup infrastructure, separate its identity plane, constrain management paths, and test recovery as a Zero Trust boundary.