ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

If you’re using a firewall, it’s not microsegmentation

Ask any UK security leader whether their organisation has implemented microsegmentation, and they’ll almost certainly tell you they have. Our research found that 94% of UK IT security decision-makers report using at least one microsegmentation approach. 

 

Near-universal adoption - that’s some extraordinary progress. As someone who has championed microsegmentation as a foundational control for Zero Trust, I can pack up my things and say that my job here is done. 

 

Well, not quite yet. As good as that statistic looks on paper, in reality, it’s far from accurate. Gartner estimates the real adoption rate is somewhere between 5 and 20%. So why is there such a large gulf between perception and reality? 

 

The answer lies in how microsegmentation is understood, and how easily it is confused with traditional forms of network segmentation.

 

Firewalls are not microsegmentation

The trusty firewall is at the centre of the biggest misconception that I see. Network-based firewalls remain the primary tool for microsegmentation, with 68% of security decision-makers reporting their use.

 

Firewalls have been at the heart of network security for decades, and they are very good at the specific task of dividing a network into broad zones. However, that doesn’t make them a reliable foundation for delivering microsegmentation.

 

Firewalls and hardware‑based controls struggle to keep pace with modern, multi‑cloud environments, where IP addresses and network locations change constantly.  The result is a patchwork of isolated security pockets that leaves teams with fragmented visibility and an incomplete picture of how their environment actually behaves.

In contrast, microsegmentation aims to provide granular visibility and containment. This enables security teams to quickly identify and stop lateral movement within their network. Essentially, with a firewall you can only secure the chunks, while with microsegmentation, you’re trying to secure the crumbs. 

 

So why do security teams equate firewalls with microsegmentation? It’s simple; we struggle to come up with a single definition for it. 

 

At its core, microsegmentation is a policy model that explicitly authorises interactions between users and assets, rather than permitting communication based solely on position within the network. A firewall will never achieve the level of granularity needed for microsegmentation, because the policy is tied to the network, not to the workload and its relationships.

 

Adding to the containment gap

The most telling signal of how deep this problem runs is what happens when organisations face a breach. 

 

If microsegmentation were genuinely in place and working, lateral movement would be limited by design. Yet, for many organisations, it remains one of the hardest and most time-consuming parts of incident response. That alone tells us that while segmentation controls may exist, they often lack the visibility, precision, or enforcement needed to deliver meaningful containment when it matters most.

 

Our research makes this gap explicit. While almost all (95%) of security leaders told us they are confident in detecting unauthorised lateral movement, nearly half struggle to stop it, and only 17% can contain a threat in near real time. 

 

This is because coarse network segmentation is no longer sufficient to stop the way modern attacks exploit trust to achieve lateral movement.  Today’s attackers move quickly, exploit implicit trust, and capitalise on overly permissive internal connectivity. Once inside, even small gaps in segmentation can provide ample room to manoeuvre.

 

It’s also clear that attackers are getting even faster, aided by developments like AI-powered automation. Research from CrowdStrike highlighted that the average time to achieve lateral movement is now just 29 minutes. 

 

Set that against our finding that more than half of organisations take hours and often days to isolate a compromised workload, and the scale of the problem becomes clear. 

 

When attacks can be planned, executed, and escalated at machine speed, the human response window, already too wide for most organisations, is no longer a meaningful unit of measure. 

 

What microsegmentation requires

Closing the gap is not a case of more or faster firewalls. It requires a shift in how segmentation is designed and enforced. One that is software-defined and decoupled from the network, application-aware, and built to operate at the speed of modern attacks.

 

Modern microsegmentation is the ability to control interactions at the workload level, consistently across on-premises, hybrid, and multi-cloud environments.

 

Underpinning all of this is deep observability into how applications and workloads actually communicate. Without that risk-based visibility, granular policy enforcement is guesswork.

 

That policy must operate on two fronts simultaneously: proactive and reactive. Proactive means assuming breach and acting accordingly by identifying lateral movement risk across the environment and reducing it before an attacker can exploit it. 

 

Meanwhile, reactive means having the ability to isolate compromised workloads fast enough to matter when an incident occurs. 

 

Closing the gap between belief and reality

Closing the gap between detection and containment means moving beyond the assumption that simply having firewalls in place constitutes microsegmentation. 

 

Instead, we need to start with the security outcomes: which lateral movement risks need to be reduced, and by how much. Then, work back to the policy and technology required to achieve it.

 

There are encouraging signs that this shift is underway. Our research indicates that more than half (62%) of organisations are now moving toward software-defined approaches, although there is some way to go before execution matches intent.

 

We also found that time to contain is now the most cited metric organisations use to track microsegmentation performance, which is the right instinct. The question now is whether the tools and policies in place can deliver against it. For most organisations, the honest answer is not yet.

 

Breaches are inevitable, and the organisations that will weather them are those that have built containment into their environments by design, not those that have convinced themselves that firewalls delivering coarse network zones are enough. 

 


 

Raghu Nandakumara is VP of Industry Strategy at Illumio  

 

Main image courtesy of iStockPhoto.com and ismagilov


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543