Why Segmentation Must Become a Resilience Strategy

5 min read
(July 28, 2026)
Why Segmentation Must Become a Resilience Strategy
10:12

During my career, I have viewed cybersecurity from both the customer and provider sides. Before joining Akamai, I served as CISO for Nordstrom Bank and led threat intelligence and incident response at Charles Schwab among other positions. Those roles gave me direct experience of the operational decisions CISOs must make when balancing security risks, business performance and limited resources.

One issue that continues to arise in my conversations with fellow security leaders is segmentation. Most organizations recognize its importance, but recognition does not always translate into implementation. Akamai research found that 90% of organizations had adopted some form of segmentation, while only 35% had implemented microsegmentation across their network environments.

This execution gap matters because organizations can no longer rely on perimeter prevention alone. Enterprise infrastructure now includes corporate networks, cloud platforms, endpoints, legacy systems, mainframes, Internet of Things devices, externally facing applications and a growing collection of AI services. Traffic moves between these environments continuously, making it harder to determine which systems are communicating, whether those connections are authorized and where sensitive information may be exposed.

Segmentation should therefore be treated as part of a broader resilience strategy. Its purpose is not simply to divide a network into zones, but to provide visibility, restrict unnecessary connectivity, reduce the attack surface and prevent an incident from spreading into a business crisis.

Why Segmentation Must Move Beyond Perimeter Defense

Security teams have traditionally concentrated many of their controls at the point where traffic enters the organization, even though most acknowledge that the conventional perimeter has largely disappeared. Prevention remains necessary, but it cannot be the only opportunity to interrupt an attacker.

I often use MITRE ATT&CK framework to demonstrate this because it maps the stages an adversary may move through, from reconnaissance and exploitation to lateral movement and impact. Each stage gives defenders another opportunity to intervene. If the initial compromise cannot be prevented, the next objective should be to detect the intrusion quickly, restrict movement and limit the resulting damage.

This changes how segmentation should be assessed. Rather than asking only whether it has been deployed, CISOs should examine whether it can reduce dwell time and contain activity before an attacker reaches high risk assets. Effective segmentation can prevent a compromised endpoint from communicating freely with critical applications, databases, payment systems,r backup infrastructure or worse case externally.

AI has made this question more urgent because it is disrupting assumptions about the time available to respond. Security teams may have planned around a familiar period for patching, investigating an alert or containing ransomware, but AI assisted attackers can identify weaknesses and act more quickly. Defenders must revisit their controls and ask how rapidly those controls can discover assets, identify unexpected connectivity and enforce a new policy.

The same principle applies when a zero day is disclosed. A security team may not be able to patch every affected system immediately, but it should be able to locate those systems, understand what they communicate with and ring fence them while remediation takes place. Segmentation can provide that visibility into east to west traffic while giving defenders a practical containment measure. Beyond traffic we need to monitor business models.

AI is also adding new forms of connectivity. Employees use public AI tools, organizations develop internal models, applications communicate through APIs, and agentic systems make decisions through machine identities and permissions. These developments increase the importance of knowing where sensitive data sits and which human or synthetic identities can reach it.

Segmentation as a Resilience Strategy Across Complex Environments

Historically the difficulty is that traditional segmentation programs can introduce more complexity than they remove. Internal firewalls and large collections of network zones tend tobe expensive to implement, difficult to change and dependent on specialist staff. Security teams may also fear blocking legitimate activity and causing their own internal denial of service incident.

A more practical approach is to apply controls at the application or server level and observe communication before enforcing restrictions. NIST Special Publication 800 207 Zero Trust Architecture describes different approaches to zero trust and segmentation , providing a useful reference for organizations reconsidering how access decisions and segmentation should work.

Monitoring first allows teams to understand normal communication patterns, identify dependencies and examine the likely effect of a policy before moving into enforcement. This reduces the risk of disrupting business activity while allowing controls to be introduced in manageable stages.

Consistency across environments is equally important. Most organizations do not operate solely in a modern cloud environment, so segmentation must work across data centers, cloud services, endpoints, legacy systems and connected devices. Requiring engineers to manage separate tools is impractical. Additionally, separate policies for each environment increases workload and makes it harder to maintain a consistent view of risk.

In my experience visibility is one of the strongest reasons to pursue this approach. When communication passes through segmentation controls, teams can ask why a database is connecting to the internet, which assets communicate with a third party or whether an unmanaged device is downloading updates directly. A connection may be legitimate, but it should not remain outside the organization’s risk assessment simply because nobody knew it existed.

This visibility can support resilience during a ransomware incident. Akamai’s study found that 79% of organizations had experienced at least one ransomware attack during the previous 24 months. Segmentation cannot guarantee that an attacker will never gain access, but it can restrict lateral movement and reduce the number of affected systems. Containing ransomware within one environment may allow the organization to recover in days rather than weeks.

Building a Segmentation Strategy Around Business Risk

Successful programs begin with a clear business case. An organization pursuing segmentation for compliance may require detailed reporting and evidence for auditors, while a public company concerned about material risk may concentrate on protecting systems whose loss could create financial or operational consequences. Both are legitimate objectives, but they lead to different priorities and measures of success.

For organizations beginning the process, I recommend building the business case around reducing the attack surface while increasing visibility. This ties into discovery and critical data prioritization. Security teams cannot protect assets they do not know about, and treating every system identically is neither effective nor efficient. Identifying sensitive applications, data and connectivity allows the organization to invest in stronger controls for the areas that could create genuine business impacts.

The same reasoning applies to APIs. Only 27% of respondents in Akamai research knew which of their APIs carried sensitive data. This is concerning because APIs are central to communication between applications, services and AI systems. Security teams need to identify which APIs create revenue, regulatory or operational exposure rather than treating the entire API estate as one undifferentiated problem.

Organizations should also consider the staffing required to maintain and improve these security controls. Specialist skills remain difficult to recruit, so technology providers should be able to assist with optimization, threat hunting and policy development rather than simply delivering a tool and leaving the internal team to manage it alone. Security controls with Natural Language Processing capabilities can also allow less experienced analysts to ask where an asset is in the environment, which protocol it uses and what it communicates with, without escalating every question to senior personnel.

Looking ahead, identity will increasingly become the edge. Agentic AI systems have identities, permissions and the ability to make decisions, which means organizations must track what those identities do and manage what they can access. When OWASP publishes guidance for Model Context Protocol security or MITRE ATLAS documents techniques affecting AI systems, CISOs should use those resources as prompts to reassess policies and controls.

Segmentation must form part of these reassessments because it provides a way to separate sensitive assets, observe communication and contain unexpected activity. The objective should be to reduce the time between an attacker entering the environment and defenders restricting lateral movement, turning days into hours and minutes into seconds wherever possible.

As infrastructure, identities and attack methods become more complex, resilience will depend on keeping security manageable. Fewer tools, consistent controls and clear visibility can help organizations adopt new technology without abandoning established guardrails. Segmentation contributes to that objective when it is designed around business risk, implemented across the full environment and measured by its ability to reduce dwell time and contain impact.