Microsegmentation Tools: Essential for Preventing Lateral Movement in Cyberattacks
Microsegmentation tools have become crucial in preventing attackers from moving sideways after breaching a system. These tools enforce granular security policies between individual workloads, applications, or devices, controlling east-west traffic inside an environment. The dedicated segmentation market is led by Illumio, while Akamai Guardicore offers a strong agent-based alternative with deep visibility.
Cisco Secure Workload suits enterprises wanting segmentation inside an existing networking stack. Other notable microsegmentation tools include ColorTokens, Aviatrix Zero Trust for Workloads, VMware NSX (Broadcom), Elisity, Zscaler, and Palo Alto.
The category splits into three architectural approaches: host agent, hypervisor/fabric, and identity/network-layer. Choosing the wrong approach can be a costly mistake, as each has its strengths and trade-offs. For instance, host agents program the host's own firewall but require deployment on every workload, while hypervisor/fabric enforces in the virtual switch or network fabric but is tied to that infrastructure.
Legacy and unmanaged systems often pose a challenge for microsegmentation tools. If a meaningful share of an estate consists of such systems, agent-based enforcement may not cover them. The requirement to support these systems should be considered early on during the decision-making process.