Forrester's assessment of what changed between its 2022 and 2024 evaluations of this market is unusually enthusiastic, and the specifics justify it.

Auto-quarantine. An emergency button for mass quarantine. Live recovery during an active ransomware attack. Forrester's note is that none of that was possible two years earlier, and that these features now appear across multiple vendor solutions.

Read that list again. Those are not preventive controls. They are things you do while an attacker is inside your environment.

Microsegmentation spent a decade being sold as prevention: divide the network so that a compromise in one place cannot reach another. The current generation still does that, and it has added a second proposition that is more honest about how incidents actually go.

From prevention to breach readiness

ColorTokens' strategy, which Forrester described as guided by a refreshingly honest vision, is to make customers breach ready.

Refreshingly honest is doing real work in that sentence. Breach ready accepts the premise that the breach happens. It is a different promise from keeping attackers out, and it is a more defensible one.

The mechanism is containment speed. Ransomware operators need to move laterally from an initial foothold to the systems that matter, and that movement takes time. An environment where every workload can reach every other gives them a clear run. An environment segmented at workload level forces them through controls that either block them or generate signal.

And when it does go wrong, the value shifts to how quickly the blast radius can be closed. Forrester's assessment of Illumio identifies exactly this, crediting it for letting the operator perform incident response activities including quarantine, mass quarantine, and live recovery during an active attack.

Live recovery is the striking one. Restoring systems while an adversary is still present, in a segmented environment where the restored systems are protected from re-infection, is a materially different situation from the traditional sequence of contain, eradicate, then rebuild.

Two years of unusual change

The Forrester New Wave: Microsegmentation, Q1 2022, authored by David Holmes, evaluated nine providers against ten criteria as an emerging market: Akamai Technologies, Aruba, Avocado Systems, Cisco, ColorTokens, Illumio, Sangfor Technologies, Unisys, and VMware.

Forrester's own summary of that edition is that it was entirely about layer 3 microsegmentation in a data centre or private cloud, with two approaches available: software agents, or infrastructure meaning switches and hypervisors.

Two years later the scope had expanded to public cloud workloads across four or more hyperscalers, microservices in both cloud and on-premises environments, operational technology and connected devices, healthcare, and the original data centre use case.

The policy sophistication moved further. Where the earlier generation used static layer 3 network rules, vendors added ports and protocols at layer 4, user and machine identities at layer 7, process-level metadata, and endpoint detection risk scores as inputs to segmentation policy.

That last item is worth pausing on. A segmentation policy that adjusts based on a workload's current risk score is not a network rule. It is a dynamic access decision informed by security telemetry, which is a different architecture from anything the 2022 field was doing.

Inside The Forrester Wave: Microsegmentation Solutions, Q3 2024

The evaluation scored eleven providers against twenty three criteria across current offering, strategy, and market presence, and included four vendors absent from the previous edition, among them Ordr and Elisity, both working to make segmentation succeed at the network switch where earlier networking approaches struggled.

Illumio placed as a Leader with the highest scores in both current offering and strategy and maximum marks in sixteen of the twenty three criteria. Forrester called it the original microsegmentation specialist and described its interface as visually informative and the most powerful evaluated, positioning it for large organisations with mature security programmes on a zero trust journey or bolstering defences against ransomware.

Cisco placed as a Leader with maximum scores in twelve criteria including network-based enforcement, DevSecOps support, and roadmap. Forrester noted that Secure Workload microsegments everything from bare metal to cloud, and that owning the network infrastructure gives Cisco strong flow and asset discovery.

ColorTokens placed as a Leader with maximum scores across a broad set including flow and asset discovery, visibility, policy management, microservices, operational technology and healthcare and connected devices, zero trust network access integration, administrative experience, incident response, vision, and supporting services. Forrester noted it was among the first vendors to provide broad horizontal policy across infrastructure, and singled out its ability to show all untagged assets, a policy administration capability most other vendors evaluated did not have. Reference customers cited support that can include on-site engineers.

Akamai placed as a Leader with maximum scores in eight criteria including flow and asset discovery, policy management, zero trust network access integration, incident response, and pricing flexibility, positioned for enterprises needing broad host support and flexible asset tagging.

The hard problem is knowing what should talk to what

Every capability above depends on somebody deciding which workloads are permitted to communicate, and that decision is where these deployments actually fail.

The information required does not exist in most organisations. Application documentation is stale or absent. The engineers who built the system have moved on. The dependency between two services is discovered when one of them stops working.

So microsegmentation begins with observation. The platform watches traffic, builds a map of what actually communicates with what, and proposes policy from observed behaviour rather than from documentation.

That is why flow and asset discovery scores so heavily across every vendor in this evaluation, and why ColorTokens' visibility into untagged assets was worth Forrester calling out. An asset nobody has classified is an asset nobody can write policy for, and it will be the one that breaks when enforcement turns on.

The observation period is also where the honest limitation appears. Traffic observed over four weeks reveals the flows that occurred in four weeks. The quarterly batch job, the annual reconciliation, the disaster recovery test, and the vendor support connection used twice a year will not appear, and each will fail the first time it runs under enforcement.

The gap between deployed and enforcing

Here is the pattern that determines whether a microsegmentation programme delivers anything, and it is rarely discussed in vendor material.

A great many deployments run in monitoring mode indefinitely.

The sequence is familiar. The platform is installed, agents are deployed, flows are mapped, and policy is generated. The team reviews it, and someone asks what happens if a rule is wrong. The answer is that a business-critical application stops working, possibly at an unpredictable moment, and the cause will be difficult to identify quickly.

Nobody wants to own that risk. So enforcement is deferred to the next quarter, then to after the next major release, then to after the peak trading period. Meanwhile the environment changes, the policy ages, and the confidence required to enforce it declines rather than grows.

The organisation now has excellent visibility into its network flows and no segmentation.

The vendors know this, which is why administrative experience, policy management, and interface quality carry the weight they do in the criteria. Forrester describing Illumio's interface as the most powerful evaluated is a comment about whether an operator can understand a proposed policy well enough to approve it.

The practical countermeasures are unglamorous. Start with a small number of high-value assets rather than the whole estate. Enforce in one direction before both. Use test-mode enforcement that logs what would have been blocked. And establish beforehand who is accountable for turning enforcement on, because in the absence of a named owner the default is indefinitely deferred.

That last point is the one to settle before purchase. A microsegmentation platform bought without a decision about who will accept the enforcement risk is a visibility tool with an enforcement engine nobody will ever switch on.

Where this sits in zero trust

Forrester's own framing is direct: security teams buy microsegmentation solutions to implement zero trust in the network.

That is accurate and it is worth being precise about which part.

Zero trust removes implicit trust based on network location. Microsegmentation is how that principle gets applied to workload-to-workload communication, which is the traffic that dominates a modern data centre and the traffic that lateral movement uses.

It sits alongside rather than inside the zero trust platform category Forrester evaluates separately, and the same caution applies to both: no product makes an organisation zero trust, because the model is a framework combining technology and non-technology decisions.

The integration point that matters most is identity. Segmentation policy expressed in terms of workload identity rather than IP address survives infrastructure change, which is why layer 7 identity became a policy input. An environment where addresses shift constantly, which describes any cloud deployment, cannot be segmented durably by network rules alone.

Which returns to the golden age framing. What changed is not that segmentation became possible. It is that it became expressible in terms that survive the environment moving underneath it, and enforceable quickly enough to matter during an incident rather than only before one.

Analyst Source

Forrester Research

Category definition, vendor inclusion, and evaluation findings in this article draw on Forrester's coverage of microsegmentation, evaluated as an emerging market in The Forrester New Wave: Microsegmentation, Q1 2022, covering nine providers against 10 criteria, and scored in The Forrester Wave: Microsegmentation Solutions, Q3 2024, covering 11 providers against 23 criteria across current offering, strategy, and market presence. Forrester evaluates zero trust platforms as a separate market.

Source research

Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.