Segmentation limits paths, not compromise itself
Segmentation does not stop anything being compromised. It limits where the compromise can go next.
That distinction matters when people judge it: a segmented network still has incidents. What it does not have is one laptop reaching the backups, the finance system and the building controls. Judging segmentation by whether you had an incident is the wrong test; the right one is how far the incident travelled.
More on Network segmentation
- Every firewall allow rule creates a permitted pathEvery rule is a hole
- Flat networks turn local trust into broad reachabilityOne floor, no walls
- Microsegmentation moves boundaries closer to workloadsMove the fence inwards
- Management paths can bypass segmentationOver the checkpoint
- Default deny makes new paths deliberateNothing moves until a lever is pulled
- Network zones should reflect trust and functionZones follow the job
