Universal Microsegmentation

Stop Lateral Movement in Hours, Not Months

Quickly deploy microsegmentation across every workload with identity-based policy, not network architecture. No firewall rewrites, no VLAN redesigns, and no blind spots.

99.99%reduction in lateral movement
0VLAN or firewall changes required
Day 1live in an afternoon — no flow-mapping project first

Watch the Demo

Watch Jerome Mills, Sales Engineer at NetFoundry, demonstrate how to simplify microsegmentation across multi-cloud environments like AWS, Azure, and GCP using the NetFoundry Zero Trust platform. Learn how to eliminate complex firewall rules, overcome network drift, and instantly secure application connectivity with software-based, outbound-only connections.

The challenge

Legacy Segmentation Takes Weeks to Months.
Attackers Take Minutes

29 min average attacker breakout time from initial access to lateral movement — fastest observed at 27 seconds1

One foothold becomes a full intrusion

However the attacker gets in, that single foothold becomes a full intrusion by moving system to system until it reaches the assets that matter. Breakout now happens in minutes, often without malware, so perimeter detection sees nothing unusual — and the legacy answer, VLANs and firewall rules, is too slow to deploy and too brittle to change to contain it.

  • Boundaries defined by IP address and network location — policy drifts as infrastructure changes
  • 100s to 1000s of rules across tools, teams, and firewalls, and roughly two weeks to make any single change
  • VLAN redesigns and firewall reviews that slow every new application, vendor, or workload
  • Visibility limited to IP and port — hard to trace activity by identity across boundaries
  • Every flow must be discovered and defined up front before segmentation can be deployed
“We have tons of policies/rules across multiple tools, firewalls, and other infrastructure to allow communication between workloads. It takes two weeks to make any change.”

CTO — National Telco, Postal, and Logistics Operator

The All-or-Nothing Trap

Months of flow discovery and dependency analysis pass before your first workload is contained, and one missed flow can break a production application. Enforcement slips quarter after quarter while the full risk stays in place.

The NetFoundry Solution

Segment by Identity, Without Touching Firewalls or Networks

NetFoundry replaces IP-based segmentation with identity-based segmentation. Access is granted per identity and service, not per subnet, and you define it as policy, change it in seconds, and start segmenting without discovering and defining every flow before you deploy. Three things make that practical:

Service levels

Segment at the right level, per service

Access per service, not per subnet

Every grant is scoped to a specific identity reaching a specific service. A workload reaches only the services policy names — nothing else is routable, and there is no subnet-wide access to exploit.

Enforce at the level that fits

Apply segmentation at the host or gateway through a connector, across the network, or in the application through the SDK. Start at whichever level is easiest for each workload, and extend over time.

Visibility

Discovery and audit, by identity

Discover, map, and visualize flows

Turn on discovery when you want it, run policy in passive mode before you enforce, and visualize flows first. Discovery runs continuously, never as a project you must finish first.

One view, by identity and service

Every connection is attributed to a named identity and service, not an IP and port, across microsegmentation, Zero Trust, and remote access in a single view.

Policy

One model, default deny, instant change

Default deny by identity

Nothing connects unless policy explicitly authorizes it. Every workload — human, machine, and AI — carries a cryptographic identity, and connections are outbound-only, so there are no inbound ports to scan.

Change in seconds, govern in one place

Adjust a boundary with a policy update, not a firewall ticket or a VLAN redesign. The same model, control, and audit apply across every environment, giving one point of governance instead of a tool per silo.

Under the hood, mutual authentication with X.509 certificates verifies identity and evaluates policy before any routable path exists — so the default is deny, the target is invisible until authorized, and policy no longer drifts as infrastructure changes.

3,000 companies trust NetFoundry — including 8 of the 10 largest US banks and 2 of the 5 largest US companies.

How it works

Four Moves to Contained, Low-Maintenance Segmentation

No flow-mapping project, no VLAN redesign, no firewall tickets — each move is policy you apply on top of the infrastructure you already run.

1

Define access by identity, not network

Each workload gets a cryptographic identity bound to it. Policy defines which identity may reach which service, independent of IP address, subnet, or location. Nothing to map first.

2

Authenticate before any path exists

Mutual authentication with X.509 certificates establishes an encrypted, outbound-only conduit only after identity and policy are verified.

3

Enforce least privilege east-west

Authorized identities reach only the specific services policy permits — nothing more. Lateral movement to anything else is structurally impossible, regardless of the network.

4

Change in seconds, audit by identity

Adjust a boundary by updating policy — no firewall changes, no VLAN edits, no two-week window. Every connection is logged by identity and service for compliance.

Want the architecture in depth — the controller, the identity model, and policy enforcement? Explore the platform →

One platform, three motions

One Model for Microsegmentation, Zero Trust, and Remote Access

Most teams run microsegmentation on one stack, Zero Trust on another, and remote access on a third — each with its own console, its own policy language, and blind spots at every border between them. NetFoundry runs all three on one identity-based model, so east-west and north-south traffic are governed the same way.

Unified Identity, Policy, Control, Visibility, and Governance
East-West

Microsegmentation

Same site. Contain lateral movement between workloads on the network you already run.

North-South

Zero Trust

Across site, admin, or technology borders. A server or API stays unreachable from the network and reachable only by authorized identities.

Remote access

Secure Remote Access

Remote admins — human or machine — get least-privileged access to a single service, not VPN-level access to the whole network.

For the CISO, that means one place to define policy and one audit trail across all three motions, rather than reconciling firewalls, NAC, VPN, ZTNA, and separate microsegmentation tools. You consolidate silos instead of adding one, and retire VPNs, firewall rule sprawl, and point tools as workloads migrate.

Deployment

Deploy in an Afternoon, Not a Quarter

Legacy segmentation is a network project: map every flow, redesign VLANs, and open a ticket for each rule change. NetFoundry is policy you stand up on top of the infrastructure you already run. You put the fire out first — contain your highest-value workload today, then extend across the estate at your own pace.

Start small

Secure one workload

Spin up protection for a single critical workload in minutes — as code, with no firewall changes, no integrations, and nothing else in your environment disrupted. Get started without waiting to map your entire estate.

And go wide

And your whole estate

Apply one identity-first policy model across cloud, datacenter, OT, AI, and third-party workloads — replacing a tangle of per-environment tools and control planes with a single way to define, change, and audit segmentation.

Legacy segmentation

  • Discover and map every flow before you can deploy
  • Redesign VLANs and re-architect subnets
  • ~2 weeks per change across teams and firewalls
  • A different tool and control plane per environment
  • Rip-and-replace risk to roll anything back

NetFoundry

  • Start segmenting Day 1 — no flow-mapping project first
  • Runs on existing infrastructure, untouched
  • Change a boundary in seconds with a policy update
  • One policy model across every environment
  • Add or revoke a segment incrementally, instantly
Every workload

One Way to Segment. Every Environment Covered.

With legacy microsegmentation, every environment and architecture demands its own approach — complex, hard-to-change rules enforced at the workload, host, hypervisor, and network layers. A typical enterprise ends up running several different tools and control planes for segmentation, with no uniform policy and no single view across them. NetFoundry applies one identity-first policy model everywhere — including the workloads traditional tools can’t reach.

AI workloads

Contain agents, models, and tools

Give AI agents, MCP servers, and LLMs sovereign identities with policy-scoped access — so a compromised agent can only reach what it is explicitly authorized to reach.

Cloud & datacenter

East-west control across hybrid infrastructure

Segment apps, VMs, containers, and Kubernetes workloads by identity across clouds and on-prem — with no changes to your infrastructure as code (IaC) or virtualization platforms, and no per-cloud firewall rules to maintain.

OT & IoT

Reach devices agents can’t

Bring least-privilege segmentation to OT, IoT, and legacy or unmanaged devices using clientless, host, or gateway options — aligned to IEC 62443 zones and conduits.

Third party

Segment partner and vendor access

Replace broad VPN tunnels with service-level access scoped to a single partner identity — granted and revoked instantly, with a full audit trail.

Borderless and universal — one identity model, reached through connectors for applications, devices, gateways, and firewalls, including turning an existing firewall into a Zero Trust enforcement point rather than ripping it out.

“We moved beyond the perimeter with NetFoundry. It delivers a strictly least-privileged access model that is incredibly easy to deploy. The management console turns what used to be a tangle of firewall rules into a streamlined, visual command center.”

Viktor Szabo, Deputy CTO, Ominimo

VMware / NSX exit

Replace NSX DFW with Segmentation That Survives the VMware Exit

NSX Distributed Firewall enforces inside the ESXi kernel, so its policy evaporates the moment a workload leaves vSphere. Migrations to Nutanix, Proxmox, or the cloud run in waves over 12 to 36 months, with application tiers split across two platforms the whole time — and the destination platform has no NSX-equivalent distributed firewall to carry the policy forward.

Segmentation that moves with the workload

NetFoundry attaches policy to the workload identity, not the vNIC or the hypervisor, so each migration wave carries its policy with it. You keep segmentation continuous across both platforms for the entire migration window, instead of leaving migrated workloads unsegmented until a firewall project catches up.

Mirror your existing DFW intent as identity-to-service policy, run it in passive mode, and turn on enforcement when you are ready — no flow-mapping project to begin. When the migration finishes, the same model still covers those workloads, and it extends to the cloud, OT, and AI estates NSX never reached.

  • Policy bound to workload identity, not the vNIC — it never depends on vSphere
  • One identity-to-service model spans both platforms for the whole migration
  • Gateways front legacy and end-of-life workloads that cannot take an agent
  • No re-IP, VLAN redesign, or firewall rule build-out to segment the new platform
  • A permanent segmentation layer after cutover — not a project that restarts from zero
Phase 1

During the migration

Overlay gateways front both platforms. DFW intent is mirrored as identity-to-service policy in passive mode, then enforced — so app tiers split across vSphere and the new platform stay segmented as VMs move in waves.

Phase 2

Steady state

Server connectors run on the tiers themselves and DFW retires for good — the same policy objects, now with no hypervisor dependency, extended across cloud, OT, and AI.

Outcomes

Smaller Blast Radius. Less Operational Drag.

Contained blast radius

A compromised identity reaches only what policy allows. One foothold stays one foothold instead of becoming a network-wide intrusion.

Invisible east-west and north-south surface

No routable path exists until identity and policy authorize it. There’s nothing to scan, discover, or exploit between workloads.

Policy changes in seconds, not sprints

Tighten or extend boundaries with a policy update. No change-control cycle, no firewall rules, no VLAN redesign.

Visibility by identity, not IP

See which identity reached which service, across every environment — meaningful, auditable insight instead of IP-and-port guesswork.

Reduced compliance scope

Identity-based isolation shrinks the systems in scope for audits and maps cleanly to segmentation mandates in PCI-DSS, IEC 62443, and NIST 800-207.

No network redesign or downtime

Works across existing infrastructure. Deploy incrementally, add segments progressively, and leave VLANs and underlay routing untouched.

Compliance, Scale, & Insurability

Built for Regulated, Segmented, and Insurable Environments.

Network segmentation is moving from a best practice to a requirement across frameworks and cyber-insurance criteria. Underwriters increasingly ask for network segmentation and least-privilege access as a condition of coverage, and identity-based segmentation gives you a clean, auditable way to demonstrate both. NetFoundry maps identity-based segmentation directly to those mandates — and runs it at the scale critical infrastructure demands.

PCI-DSS IEC 62443 NIST 800-207 NIST 800-171 NERC CIP NIS2 DORA HIPAA EU CRA SOC 2 Type II FIPS CJIS
3,000companies use NetFoundry
2 of 5largest US companies connect with NetFoundry
8 of 10largest US banks connect with NetFoundry
1B+sessions/month across global infrastructure

Built by the creators and maintainers of OpenZiti, the world’s most-used open-source zero-trust networking platform.

FAQ

Microsegmentation Questions

What is microsegmentation?

Microsegmentation is the practice of isolating individual workloads — rather than whole network segments — so that a compromised system cannot reach anything beyond what policy explicitly allows. Traditional segmentation isolates whole subnets; microsegmentation isolates down to the individual workload or service. NetFoundry does this with cryptographic identity instead of IP addresses or network location.

How is microsegmentation different from VLANs and firewall rules?

VLANs and firewall rules define access by where a workload sits on the network, so policy drifts as infrastructure changes. Identity-based microsegmentation defines access by cryptographic identity instead, so a workload reaches only the services policy names — regardless of its IP address, subnet, or location.

How is microsegmentation related to Zero Trust?

Microsegmentation is how Zero Trust is enforced east-west, between workloads. NetFoundry applies one identity-based model across all three motions — east-west microsegmentation, north-south Zero Trust, and secure remote access — so the same policy, visibility, and audit cover traffic in every direction.

Does microsegmentation require managed switches or a network redesign?

No. NetFoundry’s microsegmentation runs as a policy layer on top of existing infrastructure, with no VLAN redesign, no managed-switch dependency, and no firewall rule changes. A single workload can be protected in minutes, and the rest of the environment is left untouched.

Can microsegmentation work on OT and IoT devices with unmanaged switches?

Yes. Flat OT networks typically run on unmanaged switches, which gives VLAN- or switch-based segmentation nothing to enforce against. Because NetFoundry segments by identity instead of network position, it brings least-privilege zones to OT, IoT, and legacy devices with no change to the underlying switching infrastructure.

How does NetFoundry replace VMware NSX (DFW) segmentation during a migration?

NSX Distributed Firewall enforces inside the ESXi kernel, so its policy does not follow a workload once it leaves vSphere. NetFoundry attaches policy to the workload identity instead of the vNIC, keeping segmentation continuous across both platforms throughout a migration to Nutanix, Proxmox, or the cloud. Mirror existing DFW intent as identity-to-service policy, run it in passive mode, and enforce when ready; the same model remains after cutover and extends to cloud, OT, and AI workloads NSX never covered.

How long does it take to deploy microsegmentation?

NetFoundry customers typically protect a single critical workload in an afternoon, because there is no flow-mapping project or VLAN redesign required before deployment starts. Rollout across the estate then proceeds incrementally, at whatever pace the organization chooses.

Does microsegmentation help with compliance and cyber-insurance?

Yes. NetFoundry’s identity-based microsegmentation maps directly to segmentation requirements in frameworks including PCI-DSS, IEC 62443, NIST 800-207, and NIST 800-171, and it narrows audit scope by isolating sensitive workloads at the identity level rather than the network level. Because cyber-insurance underwriters increasingly require segmentation and least-privilege access, the same controls and per-identity audit trail help you demonstrate those requirements at renewal.

Contain Breaches. Deploy Quicker. Cut Costs.

See how identity-first microsegmentation stops lateral movement across your cloud, datacenter, OT, AI, and third-party environments — without a single network change.

  1. Average eCrime breakout time from initial access to lateral movement, and share of malware-free detections. CrowdStrike, 2026 Global Threat Report (Feb. 2026). crowdstrike.com