Micro-Segmentation
Fine-grained rules between servers and applications that stop an intruder moving from one compromised system to the next.
- NIST CSF 2.0 functions
- Protect
- Relevant for
-
- Banking and financial services
- Telecommunications
- Government and public sector
- Oil and gas
Overview
Once inside, attackers move from server to server looking for data and administrator rights. In most data centers, a compromised machine can reach almost everything else.
We help you map how your applications really communicate and allow only the connections they need, so one intrusion stays small.
What you get
- Critical applications and data reachable only from the systems that need them
- An intruder on one server contained, instead of free to move across the data center
- A visual map of how applications talk to each other
- Rules that follow workloads when they move
What we cover
- Application dependency mapping
- Segmentation policy by application, environment and data sensitivity
- Enforcement at the host, hypervisor or network level
- Protection of east-west traffic inside the data center and cloud
- Policy testing before enforcement
- Logging and alerting on blocked connections
How we work
-
Map
We discover how applications communicate and group workloads by function and sensitivity.
-
Design
We design policies, starting with your most critical applications, and choose where each is enforced.
-
Test
We run policies in monitor mode and review what would have been blocked.
-
Enforce and hand over
We enforce in stages, document the policy model and train your teams to change rules safely.
Deliverables
- Application dependency map
- Segmentation policy design
- Deployed and tested enforcement
- Documentation and administrator training
Questions buyers ask
Is micro-segmentation the same as network segmentation?
No. Network segmentation divides the network into zones, usually by VLAN and firewall. Micro-segmentation controls traffic between individual workloads inside a zone.
Will it disrupt running applications?
Not if introduced carefully. We learn real traffic first, test rules in monitor mode and enforce one application group at a time.
Related offerings
-
Next-Generation Firewall (NGFW)
Next-generation firewalls that control traffic by application, user and content, with a clean, documented rule base.
NIST CSF function: Protect -
Network Access Control (NAC)
Control which devices and users may connect to your wired, wireless and remote networks, and place each one in the right network segment automatically.
NIST CSF function: Protect -
Network Detection & Response (NDR)
Visibility into network traffic to detect lateral movement, command-and-control and data theft that endpoint tools cannot see.
NIST CSF function: Detect