Microsegmentation software is a network security solution designed to divide workloads and control them individually using policy-driven, application-level security. These tools isolate components of data centers and cloud workloads using network virtualization to deploy and protect them independently. This helps companies better visualize their assets and workloads to improve visibility, detection, and remediation time all while eliminating an attacker’s ability to move laterally throughout the network.
Companies use microsegmentation to both improve protection on individual workloads and improve network observability. When components of a data center or other environments are compromised without microsegmentation, attackers may be allowed to jump from one asset to the next, moving laterally throughout the network. With microsegmentation in place, the attack surface greatly reduces using granular security controls and policy-based security triggers to protect workloads even once attackers penetrate perimeter defenses.
Microsegmentation technology is often used to achieve zero trust security architecture, but should not be confused with zero trust networking software. While there is some overlap between the two categories, zero trust networking solutions are designed specifically to manage identities and control privileged access to internal applications or computing environments. While microsegmentation technology is also used for application-level security, the tools are more focused on creating secure zones, establishing security policies, and isolating workloads individually.
To qualify for inclusion in the Microsegmentation Software category, a product must:
- Utilize network virtualization to isolate application workloads
- Restrict lateral access across networks, data centers, and cloud environments
- Dynamically adjust policies to ensure consistent workload protection