For as long as I’ve been in cybersecurity, we’ve been trying to “adapt to the shifting threat landscape.” More recently, a number of vendors and security leaders alike have told me some version of a joke about how starting a microsegmentation project is a great way to get fired. But this is a market that has moved aggressively to carve out a niche that addresses emerging threats, as well as the implementation challenges that — facetiously or otherwise — caused microsegmentation to be viewed as a catalyst for career moves.

Regulatory regimes recognize the importance of network segmentation and are placing greater emphasis on it, up to and including mandating its use. The solutions themselves are also evolving to bring value to personas and teams outside of traditional network security. Throughout this evaluation, several themes appeared repeatedly:

  • Any Zero Trust strategy without microsegmentation is incomplete. Zero Trust Network Access (ZTNA) partially scratched a Zero Trust itch when many users were still remote, but it was usually separate from data center segmentation and rarely covered campus networks — especially after employees returned to the office. Whether it’s couched as Universal Zero Trust Network Access (UZTNA) or café/coffee shop-style networking (which is another blog post for another day), there’s no getting around the fact that microsegmentation picks up where conventional ZTNA leaves off and that it’s an essential component of coherent Zero Trust policy enforcement.
  • The Mythos “moment” is driving new interest in microsegmentation. Security and risk pros have been bemoaning our collective ability to patch quickly enough for time immemorial, but nothing has cast that issue into such sharp relief as the emerging capabilities of frontier models (and well-harnessed open-weight models, for that matter). In an environment where patching ultimately becomes a second-order remediation — or isn’t possible at all, as is the case for some systems — containment is the only viable option. And the shortest path to making containment feasible (i.e., doesn’t involve massive infrastructure changes) is enforcement that is decoupled from network topology.
  • Microsegmentation helps plumb the depths of technical debt. When it comes to the “way things work” (a.k.a. “what talks to what”), the disconnect between network and security teams and their application developer/owner counterparts has always been… profound. Although the early days of microsegmentation were marked by significant manual effort that involved complicated — and often inadequate — collaboration between these constituencies, the automation capabilities in current microsegmentation solutions help eliminate a lot of heavy lifting and bridge what can otherwise be a very large divide. Alfred Korzybski wasn’t talking about real cartography — let alone network or application dependency maps — in his famous observation that “the map is not the territory” but current microsegmentation solutions, nevertheless, offer an elegant solution to the ontological conundrum he identified (in the context of cybersecurity, at least). They also offer a unique and valuable way to capture and maintain institutional knowledge that has a habit of getting lost, buried, or forgotten.

Despite being a solution in a relatively clear-cut problem space, there is still considerable nuance, variety, and differentiation across microsegmentation solutions. Read the full report for all the insights we gathered from our deep-dives with participating vendors and their customers: The Forrester Wave™: Microsegmentation Solutions, Q3 2026.

If you’re a Forrester client and would like to discuss the results or where the market goes from here, book an inquiry or guidance session with me.

Share