Illumio is a Leader and a Customer Favorite in The Forrester Wave™: Microsegmentation Solutions, Q3 2026.

The Zero Trust Hub Editions

Zero Trust trends, insights, and resources for today’s cybersecurity leaders

Subscribe on LinkedIn
September 14, 2026
Want more Zero Trust trends, insights, and resources?
Explore Past Editions

The Monday Microsegment for the week of 9/14/2026

NEWS

Is Your Cyber Stack Actually Working, or Is It Just Running?

In TechRadar, Michael Adjei makes the case that a bigger security stack buys less safety than it promises. Real strength comes from controls that talk to each other — validating threats continuously across identity, visibility, and enforcement.

Read more
NEWS

CISOs Still Get All the Blame and None of the Budget

In Bloomberg, Illumio makes the case that CISOs carry the blame for breaches without the authority, budget, or boardroom standing to stop them. Give security leaders a real seat at the table, and cyber risk becomes what it already is: a shared executive responsibility.

Read more
THE WEEKLY BRIEFING

Venice Learned to Contain a Breach in 1423. We’re Still Catching Up.

Raghu Nandakumara
VP, Industry Solutions

In 1423, Venice built a hospital on an island in its lagoon and held every arriving ship there for 40 days before anyone aboard could come ashore. It’s one of the oldest containment policies on record. And six centuries later it’s still the one most security programs skip.

The city had no theory of contagion and no way to tell a healthy ship from a plague ship at the harbor mouth. So the Venetians changed the question. Once a ship docked, how far could its crew go, and for how long?  

The answer was a holding zone, escorted movement, and hard limits on where a crew could go once ashore. It’s where we get the word quarantine: quaranta giorni, 40 days.

Today, most of our security spending still sits at the harbor mouth. Firewalls, gateways, and detection tooling all work on what gets in, and little of it follows traffic once it’s inside. That leaves the question that decides how bad a breach gets: how far can an attacker travel after they land?  

Zero Trust puts that question at the center of the architecture. Microsegmentation is how you answer it. It applies least-privilege access inside your environment, so a compromised workload can reach only the systems it needs to do its job — and nothing else.

Containment is a decision you make before the attack. And it’s a topic I wrote about in John Kindervag’s new book, Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era, out this October.

Absence makes the budget wander

Almost nobody argues against segmentation anymore. The disagreement shows up at funding time: the program gets scoped down to a pilot, and the pilot gets pushed to a quarter with more room in it.

Segmentation is easy to defer because it works in the opposite direction from detection. Detection reports what’s happening in the environment, so every alert it raises is evidence that it’s earning its budget. Segmentation keeps things from happening and leaves nothing to report.

At budget time, detection brings the board incidents raised, response times, and a line moving up and to the right. Segmentation brings a quarter where a breach never turned into a major cyber incident and operations continued as normal. Budget follows the controls that can show their work.

So segmentation waits, the way it waited through client-server, virtualization, and the move to cloud. The argument holds steady each time: the platform is moving fast, segmentation would slow it down, and controls can wait until the migration settles.  

Migrations never settle, and controls added later always cost more.

Lateral movement is where the money is

IBM’s Cost of a Data Breach Report 2026 puts the global average cost of a breach at $4.99 million. Most of it goes to detection, escalation, and lost business, so the size of the bill follows the size of the attack’s blast radius. The blast radius is a function of reachability, and reachability all comes down to how your architecture is designed.

Attackers have worked this out. Verizon’s 2026 Data Breach Investigations Report found ransomware in 48% of breaches, and 69% of victims refused to pay. When most targets won’t pay for a decryption key, the leverage has to come from somewhere else — so extortion groups have shifted from locking files to causing as much operational disruption as they can.

Reach is the product now. Segmentation goes straight at that business model, because it takes away the reach that makes the extortion pay.

AI runs the old playbook faster

Then AI arrived.  

Last July, Sysdig documented JadePuffer, a ransomware operation run end to end by a large language model (LLM). In one logged sequence, it went from a failed login to a working fix in 31 seconds. Two weeks later, Hugging Face disclosed a breach in which autonomous agents from OpenAI escaped their sandbox, harvested credentials, and moved into internal clusters.

Strip the AI out of either incident, and you’re left with an unpatched internet-facing service, credentials reused where they shouldn’t have worked, and movement into systems the agents had no business touching. That’s lateral movement at its most basic.  

Attackers are still using the same playbooks as they always have. What’s changed is how fast they can run through them. When an intruder can fail, adapt, and succeed inside half a minute, containment has to be in the environment already, enforced without waiting for anyone to approve it.

Nobody gets 40 days anymore

Venice got 40 days because ships were slow. But nothing in your environment today moves slowly.  

Agentic AI is about to put more non-human identities in your network than you’ve ever managed, each holding credentials and reaching across systems by design. Every quarter you delay adding breach containment adds paths to map, policy to write, and cost to work you’ll end up doing anyway.  

So start small. Pick the one system you can’t afford to lose and draw a boundary around it before an attacker maps the route for you. A single enforced boundary this quarter does more for you than a perfect plan next year.

Venice worked this out in 1423 without knowing what it was fighting. We know exactly what we’re fighting, and we already have the tools to contain it. The only thing missing is the decision to use them.

Get a first look at Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era. Download your exclusive preview today.

Read more
STATSHOT

The Threat Has a URL

Malicious activity in 2025 was overwhelmingly tied to URLs, not files. URLs accounted for 98.3% of all detections, while files made up just 1.7%. That means URL-based detections outnumbered file-based detections by more than 56 to 1. The threat wasn’t primarily hiding in an attachment. It was waiting behind a link.