Just Launched Gruve PulseAI Platform, your private AI infrastructure, production-ready in under 2 weeks.PulseAI is live — private AI, ready in 2 weeks.

See PulseAI
Blog

Why segmentation is the new firewall

August 10, 2026

When a board asks me about security, the question is usually: are we funding security projects adequately and are we secure with our current funding?

The question I would rather be asked is simpler. If someone breaks into our environment at 6am in the morning, how far can they go by the time everyone comes to work?

That question has an answer. It is detectable, it is testable, and the answer is determined almost entirely by our ability to take appropriate action to prevent any damage to the business.

I opened this series by arguing that AI has collapsed the time defenders used to have between a weakness or vulnerability being discovered, and it being exploited before an organization has the opportunity to fix it. If that is true, and I believe it is, then the controls that matter most are the ones that work after someone is already inside. There are two, and they belong together.

Most attacks do not start where people think

In my experience, and in nearly every incident review I have sat through, the attack does not begin with a firewall failure. It begins somewhere much more ordinary:

  • Phishing
  • Stolen credentials
  • A zero day vulnerability
  • A compromised laptop
  • A vulnerable server
  • A compromised AI application
  • Third party software

Any one of those puts an attacker inside, holding something that looks like legitimate access. What happens next is what decides whether you have an incident or an outage.

Once inside, attackers typically move laterally. That lateral movement is responsible for most ransomware spread we have seen. The initial compromise is rarely the interesting part of the story. The outbreak is.

What segmentation actually is

Segmentation is the practice of dividing an IT environment into smaller, logical security zones where communication is explicitly allowed or denied based on business policy.

Put plainly:

Without segmentation. Every IT system can potentially talk to every other system. If one system is compromised by ransomware, it spreads easily to the others and can bring down the entire network.

With segmentation. Every communication is intentional, authenticated, inspected, and logged. With Cisco ISE and TrustSec, we create logical segmentation that prevents ransomware from spreading, and the policy is implemented across your entire IT infrastructure.

That is the whole idea. It is not exotic. It is a discipline most organizations have deferred because flat networks are easier to design and run, right up until the day they are not.

Why I say it is the new firewall

The firewall was built for a world with a clear inside and a clear outside. That world is gone. Identity is the new boundary now, and identity travels. It shows up on employee, contractor, and partner desktops, and increasingly in AI agents that hold credentials and act on their own.

So the control that matters most is no longer the one at the edge. It is the one that decides what an authenticated identity is permitted to reach once it is already inside.

That is segmentation, the control that prevents the spread and determines the size of the incident.

Observability and segmentation are one system

This is the part I want boards and CIOs to internalize, because the two are usually funded as separate projects and they should not be.

Segmentation answers the question of what is prevented, where observability gives you a view into what is going wrong.

Together, they create a complete picture. Visibility without enforcement is a very expensive way to watch an incident unfold. Enforcement without visibility is policy written blind, and it tends to break the business.

There are several solutions available for observability, and one of the leading solutions is Cisco Splunk. Once you know what normal looks like, you can write a segmentation policy that reflects how the business actually operates instead of how someone assumed it operates several years ago.

Compliance is easier when isolation is enforced

Segmentation simplifies compliance because it enforces data isolation as a matter of policy rather than wishful thinking.

Healthcare. Isolating clinical systems from administrative networks supports HIPAA requirements, and it is also what keeps imaging, pharmacy, and scheduling running when something reaches the administrative side.

Financial services. Restricting payment environments helps support PCI DSS compliance, and it is the difference between a contained event and a reportable breach of the cardholder data environment.

The benefit is business resiliency with compliance.

What boards should ask their CIO

If I had five minutes in a board meeting, these are the questions I would want asked. None of them require a technical answer. All of them require an honest one.

1. If credentials from one business unit were used against your other business unit, what would be the consequences?
If nobody can answer with confidence, segmentation is the first project.

2. How long would it take us to notice that we have been targeted?
If the honest answer is measured in weeks, then observability is the second project.

3. Are our environments (clinical, payment, production) logically separated from non-critical infrastructure?
Segmentation should have been implemented, just not outlined in a future plan.

4. Do our AI applications and agents have default unrestricted access?
An agent with default access to everything is a segmentation problem in disguise.

5. Do you have a process or tool in place to validate network segmentation policies?
Every communication in a segmented environment is authenticated, inspected, and logged. That log is the proof.

Where to start

Start by mapping users and business applications today to get your first view of what segmentation map needs to look like. Most organizations will find they are surprised when they develop their first segmentation map.

Then segment the environments where an outage is unacceptable first. Clinical systems. Payment environments. Manufacturing lines. Do not attempt the entire enterprise in the first go. Prove the model where the consequences are highest, then expand.

Run observability and segmentation as one initiative with one owner. Visibility informs policy, policy generates new telemetry, and the loop tightens over time.

The point

Prevention matters, but continuity provides business resiliency.

There is a high probability that an attacker may infiltrate into your network, however, proper segmentation and observability will allow you to detect and remediate faster.

It is a segmentation and observability question that the board should be asking now.

Unlock your
true speed to scale

Accelerate what data and AI can do together.

Before you go - don’t miss what’s next in AI.

Stay ahead with Gruve’s monthly insights on trusted AI, enterprise data, and automation.