The 2025 Cisco Segmentation Report, with 1,000 respondents, was launched final month and has prompted me to suppose extra deeply concerning the evolution of the decades-old cybersecurity idea and the way it continues to adapt to fulfill the wants of recent enterprises. I beforehand wrote that whereas 79% of respondents take into account segmentation a prime precedence, solely 33% implement it absolutely. The survey outcomes additionally revealed attention-grabbing insights into why segmentation stays a foundational idea.
The evolution of segmentation and the event of various segmentation approaches make the idea excellent for implementing a proactive method to enterprise cybersecurity at present. For years, organizations have utilized macro-segmentation to divide networks into smaller sections, which helps restrict the unfold of profitable assaults whereas enhancing total resilience. And now, augmenting macro-segmentation with micro-segmentation implementations permits safety groups to separate environments into separate networks AND isolate particular workloads based mostly on habits or identification. This twin segmentation method is well-suited to guard at present’s distributed, cloud-first community infrastructure and the purposes, information, and customers that depend on these crucial networks.
That is the primary a part of a three-part collection that delves deeper into the survey outcomes and what they reveal concerning the present state of segmentation.
Macro-Segmentation (On It’s Personal) Is Not Sufficient to Meet As we speak’s Cybersecurity Challenges
Macro-segmentation alone is inadequate because of current adjustments in fashionable utility structure. Fashionable purposes are now not monolithic, and they’re now not constrained by a subnet or VLAN. Consequently, these purposes are decentralized and composed of a number of workloads. This new decentralized structure has boosted utility efficiency, scalability, maintainability, and reliability; nevertheless, it has made it difficult to grasp what’s occurring on the workload stage.
Nevertheless, the shortage of visibility and management on the workload stage makes conventional safety approaches (together with macro-segmentation) difficult. It’s no surprise that cybersecurity groups are struggling to guard at present’s extremely distributed, cloud-first digital infrastructures.


Organizations Have to Implement Macro-Segmentation and Micro-Segmentation in Tandem
Augmenting macro-segmentation with micro-segmentation implementations permits safety groups to separate IT environments into sections whereas isolating particular person workloads based mostly on their habits or identification. This permits a proactive method to cybersecurity, leading to quicker restoration occasions, improved operations, and constant enforcement of segmentation insurance policies.
1. Faster Restoration Occasions
Respondents from organizations which have absolutely carried out each macro- and micro-segmentation report that breach containment and restoration take a mean of 20 days to finish. In distinction, respondents from organizations that haven’t absolutely carried out each macro- and micro-segmentation report that restoration takes them a mean of 29 days.


This can be a huge, huge deal. Reducing restoration time by one-third limits the breach’s affect and prevents its future unfold. Simply think about the harm that risk actors can inflict in these further 9 days. The mix of macro- and micro-segmentation slows down attackers. It additionally offers defenders with extra visibility and management over particular person workloads, providing insights into the assault chain that allow them to rapidly establish which property have to be quarantined, taken offline, and recovered.
2. An Alternative to Align Groups
Segmentation initiatives require coordination throughout a number of groups with a number of layers of duty, necessitating full alignment all through the group. For instance, a improvement workforce is aware of who created an utility, however it could not have visibility into who’s utilizing the appliance or how the appliance is getting used. A failure to coordinate throughout groups can result in over-permissioning—a typical mistake that creates important dangers for organizations.
In accordance with the survey, organizations (typically) depend on three separate groups for implementing and managing segmentation—IT infrastructure or community (87%), Safety/ SecOps (77%), and DevOps/ Cloud Engineering (71%). The method of implementing each macro- and micro-segmentation can enhance alignment between these groups and remove a lot of the danger related to over-permissioning. Persevering with with our improvement workforce instance, the drive towards segmentation can convey the event workforce nearer to these managing and securing the community by establishing a typical vocabulary and shared targets.
Amongst survey respondents at organizations which have absolutely carried out each macro- and micro-segmentation, 87% report that their groups are absolutely aligned, in contrast with 52% of these at organizations with out full implementation.


3. Constant Enforcement
In accordance with the report, two-thirds (63%) of respondents at organizations with full implementation strongly agree that automation is vital to scaling and maturing segmentation initiatives, versus 50% with out full implementation of each. Automation permits organizations to scale their segmentation insurance policies throughout your complete group (or a minimum of the place it is sensible), leading to extra complete and constant enforcement, and in the end, stronger safety controls. Organizations that don’t make use of satisfactory automation should manually create and keep insurance policies, which may simply fall behind safety necessities over time.


A Twin Method Permits a Proactive Cybersecurity Technique
The power to implement micro-segmentation at scale together with macro-segmentation has develop into foundational to fashionable enterprise safety methods and the zero-trust safety mannequin. This permits organizations to recuperate extra rapidly, higher align their groups, and implement segmentation extra constantly—together, permitting for a proactive method to cybersecurity. Though segmentation is an previous idea (from an IT perspective, in fact), it stays a crucial part of a proactive enterprise safety method—primarily because of its adaptation for contemporary environments.
In my subsequent weblog, I’ll define the challenges organizations are going through at present when implementing segmentation initiatives. Within the meantime, obtain the 2025 Cisco Segmentation Report to raised perceive the state of segmentation at present.
We’d love to listen to what you suppose! Ask a query and keep linked with Cisco Safety on social media.
Cisco Safety Social Media

