
The Zero Trust Hub Editions
Zero Trust trends, insights, and resources for today’s cybersecurity leaders
Why “Later” Is the Most Expensive Word in Zero Trust

Analyst Relations Director
Where does microsegmentation belong on a Zero Trust roadmap?
The answer many teams give is “later.” They work on identity first, then the network, then maybe microsegmentation once everything else settles down.
The new Forrester Wave for Microsegmentation Solutions, Q3 2026 makes that order hard to defend. Sizing up the market, the firm writes that microsegmentation “can and should play a larger role in organizations,” and points to how much easier these tools have become to deploy and run. The technology got simpler while the environments it protects got harder.
That shift should change how you sequence a Zero Trust architecture. Zero Trust sets the rule: verify every connection and grant only the access a system truly needs. Microsegmentation is the control that enforces that rule between systems, which is why it belongs early in the plan instead of at the end of it.
Why microsegmentation belongs in your Zero Trust architecture
Zero Trust is an architecture rather than a product, and it rests on least-privilege access. This means nothing gets more access than its job requires.
Most teams apply that idea well to people. Identity tools decide who can open which app, and multi-factor authentication (MFA) tools prompts back it up. Then the traffic reaches the data center or the cloud, and the rules mostly stop. Workloads talk to each other freely because they always have.
That gap is where attackers do their best work. A stolen credential or an unpatched server gets them in the door, and flat internal traffic carries them the rest of the way. Least-privilege access that ends at the login screen leaves the whole east-west path open.
Microsegmentation closes that path. It sets policy between workloads, so a web server can reach the one database it needs and nothing more. That’s the same principle identity teams already apply to people, pointed at machines instead.
Least-privilege access has to reach the workload layer
The Forrester report is useful here because it treats microsegmentation as a broad control instead of a data center feature. Forrester notes that microsegmentation can deliver “important capabilities outside of network security.”
That framing matches what security teams are dealing with in real time. Workloads now run across hybrid cloud, containers, endpoints, and operational technology. A Zero Trust strategy that covers only one of those leaves the rest on trust, and attackers are good at finding the seam.
The practical test is simple. Pick your most sensitive application, and ask what could reach it right now if a laptop in another building were compromised. If nobody on your team can answer, least-privilege access hasn’t reached the workload layer yet.
Why waiting on microsegmentation gets expensive
The “later” answer for microsegmentation in a Zero Trust strategy is worrying. Attackers have compressed their timelines, and automated tooling now moves from first access to lateral movement in minutes inside environments that keep getting more connected every day.
Microsegmentation rewards the teams who start early. Identity policy can change in a sprint. But mapping how thousands of workloads talk, then writing policy around them, produces something more durable: a working picture of how the business runs, agreed to by the application owners who know it best.
That picture takes time to build, and it keeps paying off long after the rollout ends. Teams who start before an incident get to do that work calmly, with room to test and tune.
This Wave report gives security leaders a clear argument for the budget conversation. Microsegmentation is what makes least-privilege access true where attackers actually operate, and every quarter you put it off is another quarter your east-west traffic runs on trust you never meant to grant.
STATSHOT
Where Attackers Strike
From July 2025 through June 2026, threat actors targeted technology more than any other industry, with intrusion activity rising another 5%. Financial services also saw a sharp increase, up 11%, while academic organizations rose 17%. Most other sectors saw fewer intrusions than the previous year, including telecommunications, which fell 23%. The data shows threat actors concentrating more of their activity on a smaller group of high-value industries.
