At A Glance
- Licensing is the cheapest part of microsegmentation. The recurring cost is the labor to write and maintain address-based policy, and that labor grows with every workload, cloud, and IP change.
- Manual policy management also creates risk. Gartner predicted that through 2023, 99% of firewall breaches would trace to firewall misconfigurations.
- An identity-first, software-defined model makes identity the unit of policy, so one policy model spans every environment and maintenance effort stays roughly flat as the environment grows.
Microsegmentation Series ยท Part 2 of 6
The license fee is the cheapest part of traditional microsegmentation. What shows up on next year’s budget, and every budget after it, is the labor to keep the policy alive. Traditional microsegmentation enforces at the network layer, so someone has to write and maintain firewall rules, security groups, and access control lists across every workload, in every cloud, for as long as the program runs. That recurring line item is where the return on a microsegmentation project quietly disappears. Measuring that return starts with a clear definition of what microsegmentation ROI should count.
What Is Microsegmentation ROI?
Microsegmentation ROI is the value a microsegmentation program returns, measured against its full cost of ownership over several budget years. Microsegmentation itself is one of the five pillars of Zero Trust: it isolates individual workloads so an attacker who compromises one can’t move laterally to the next. The full cost of ownership includes the license, the staff time to create, audit, and update policy, the infrastructure projects segmentation triggers, and the tooling that monitors whatever segmentation leaves reachable. At NetFoundry, we model it on a three-year view, because the cost gap between infrastructure-based and software-defined segmentation widens every year the environment changes. Business cases that stop at the license and the deployment project overstate the return of the infrastructure model.
The Hidden Cost of Microsegmentation Lives in Firewall Policy Management
Infrastructure-based segmentation ties every rule to an address. When a workload moves, an IP changes, or a subnet gets re-carved, a person has to find the affected rules and rewrite them. Across thousands of workloads and the multiple clouds most enterprises now run, that upkeep becomes a standing headcount cost. It lands on top of cloud budgets that are already strained: Flexera’s 2026 State of the Cloud Report found that 85% of organizations cite managing cloud spend as a top challenge.
The same labor also creates risk. Gartner’s widely cited misconfiguration prediction points directly at the human error that manual rule changes invite. Cisco’s 2026 Segmentation Report, a study of 400 failed segmentation projects, found that 9% collapsed from what Cisco calls operational drag, where sound projects failed under the burden of creating and maintaining segmentation policy. The organization pays twice, once for the staff time and again when a mistyped rule opens a path the team believed was closed.
Software-Defined Microsegmentation Changes the Unit of Cost
An identity-first model changes what the organization pays to maintain. Access follows the cryptographic identity of each workload, so policy states which identity may reach which service, and that policy holds when the workload moves, when its IP changes, and when the same private address range appears in three different clouds. NetFoundry calls this model Identity-First Reachabilityโข. Our fabric makes identity the unit of policy, which largely removes the treadmill of chasing address changes.
The same shift collapses the tool sprawl that inflates the infrastructure model. Overlapping IP ranges across cloud, private, and carrier networks normally force re-addressing projects or a stack of network address translation gear. An identity-based fabric connects workloads across those overlapping ranges with no re-addressing. One policy model spans every environment, which means fewer consoles, fewer specialists, and fewer places for a rule to drift out of sync.
Going Dark Removes Whole Categories of Security Spend
The largest saving is the one most business cases miss, because it sits in other teams’ budgets. On the NetFoundry fabric, every endpoint dials outbound to reach a service through a connector, and nothing listens for inbound connections. With no open ports facing the network, a protected workload stays invisible to anything that identity and policy haven’t already authorized, a posture practitioners call going dark.
When the reachable attack surface shrinks that far, the tooling built to catch what slips through has less to catch. Much of the spend on lateral-movement detection, east-west traffic inspection, and the threat-hunting hours that follow each alert compensates for a flat, reachable internal network. Limiting reachability to what policy explicitly allows lets security leaders right-size those investments and stop adding to them every budget cycle.
Going dark also reduces exposure to the most expensive number in security. IBM’s 2026 Cost of a Data Breach Report puts the global average breach at a record $4.99 million, up 12% over the prior year, with a mean of 247 days to identify and contain a breach.
Building the Three-Year Microsegmentation Business Case
Put the two microsegmentation models side by side on a three-year view. The infrastructure model shows a modest license and a large operating cost that rises each year: staff to write and audit rules, re-addressing projects, translation appliances, and the detection and response tooling a reachable network demands. The software-defined model shows the platform cost and a much smaller operating line that stays flat, because identity-based policy doesn’t add maintenance work every time the environment changes.
When the CISO takes that comparison to the CFO, the case comes down to direction. Infrastructure-based microsegmentation adds operating cost as the environment grows, while identity-first, software-defined microsegmentation holds that cost roughly flat. Over a normal budgeting horizon, that difference is the return.
If you’re new to the series, start with Part 1, The Microsegmentation Trap. Part 3 turns from the balance sheet to the threat model, and to why a growing number of CISOs now consider network-level segmentation insufficient on its own.
NetFoundry provides Zero Trust connectivity for machine and human workloads and delivers microsegmentation as policy on top of existing infrastructure, with no VLAN redesigns and no firewall rule changes, so security teams can start with one workload and expand at their own pace. To see the flat operating line in practice, watch the NetFoundry Zero Trust microsegmentation demo.
Frequently Asked Questions
What is the ROI of microsegmentation?
The ROI of microsegmentation is the value a segmentation program returns compared with its total cost over several years, including licensing, the staff time to maintain policy, and the tools needed to monitor what stays reachable. At NetFoundry, we find the biggest variable is ongoing maintenance, because rules tied to IP addresses need rework every time infrastructure changes, and rules tied to identity stay valid through those changes. It works like comparing two cars: the sticker price matters far less than what each one costs to keep on the road for three years.
Why is traditional microsegmentation expensive to maintain?
Traditional microsegmentation writes firewall rules against IP addresses, and those addresses change constantly as workloads move between servers and clouds. Each change means someone has to find and rewrite the affected rules, much like updating every entry in an address book each time a friend moves. NetFoundry ties access to a workload’s identity, so our policies stay valid when addresses change.
What is the difference between infrastructure-based and software-defined microsegmentation?
Infrastructure-based microsegmentation enforces rules in network equipment, such as firewalls and security groups, based on IP addresses. Software-defined microsegmentation enforces rules in a software layer based on the cryptographic identity of each workload. NetFoundry uses the software-defined approach, so one policy model covers every cloud, data center, and site without re-addressing. For a finance team, the practical result is that the ongoing maintenance cost stays roughly flat as the environment grows.
What does “going dark” mean in network security?
Going dark means a service has no open inbound ports, so nobody scanning the network can find or reach it. NetFoundry achieves this by having every endpoint make outbound connections only, and our platform authorizes each connection by identity and policy before any traffic flows. A useful comparison is a business with no public phone number that places every call itself, and only to people already on its approved list.
How does microsegmentation reduce the cost of a data breach?
Microsegmentation reduces breach cost by limiting how far an attacker can move after the first compromise, which shrinks the number of systems and records exposed. IBM’s 2026 Cost of a Data Breach Report puts the global average breach at $4.99 million, with an average of 247 days to identify and contain one. NetFoundry also removes inbound listening ports, so any service that policy doesn’t authorize a user or workload to reach is never exposed to connection attempts.
