Segmentation needs tested failure behaviour
What happens when the thing enforcing segmentation fails is a decision you should make deliberately.
Fail open and an outage silently removes your boundaries at the worst possible moment. Fail closed and a fault takes the business down. Both are defensible; neither should be discovered during an incident. It is worth knowing which one you have, because most organisations do not.
More on Network segmentation
- Segmentation limits paths, not compromise itselfBulkheads, not armour
- Every firewall allow rule creates a permitted pathEvery rule is a hole
- Flat networks turn local trust into broad reachabilityOne floor, no walls
- Microsegmentation moves boundaries closer to workloadsMove the fence inwards
- Management paths can bypass segmentationOver the checkpoint
- Default deny makes new paths deliberateNothing moves until a lever is pulled
