microsegment.io

segment all the things

Your Microsegmentation Policy Is Not Proven Until You Test The Deny

A clean rule set is not evidence that lateral movement paths are closed

Microsegmentation only reduces blast radius when denied paths are tested from real workloads. This article presents a practical method for validating policy enforcement, identity context, failure behavior, and containment over time.

When The Network Infrastructure Lies

Fire Ant shows why routers, TACACS, and telemetry systems need separate containment and evidence paths

Sygnia's Fire Ant investigation shows how compromised routers and authentication infrastructure can provide reach, steal credentials, and suppress the evidence defenders rely on. This article turns the incident into a practical microsegmentation and forensic-readiness design.

The Login Worked. The Breach Did Not.

A stolen identity session should not become access to every application behind the identity provider

ReliaQuest's August 2026 social-engineering attempt shows why authentication is only the first policy decision. This article explains how device trust, per-application authorization, session controls, and microsegmentation contain a valid but hostile login.

Your CI/CD Runner Is A Privileged Workload. Contain It.

The Snowflake GitHub Actions flaw shows how one untrusted issue title can become a path into an internal SaaS system

Wiz's Snowflake disclosure shows why CI/CD runners need microsegmentation, narrow egress, short-lived identity, and explicit trust paths. This article turns the incident into a practical containment design.

OT Segmentation Must Survive Edge Compromise

The Polish energy-sector attack showed why VLANs are not containment when one administrator can reach every control subnet

CERT Polska's investigation of the December 2025 energy-sector attack shows how compromised VPN and identity control paths can flatten OT segmentation. This article turns the incident into a practical containment design for remote sites, SCADA, RTUs, HMIs, and safety-critical systems.