Zero Trust is everywhere now, but ask five people what it means and you’ll get five different answers. Identity teams think authentication. Network teams think enforcement. Security leaders are stuck trying to stitch those pieces into something that actually reduces risk.
Segmentation is where those priorities meet. It determines which workloads, applications, users, and systems are allowed to communicate, and how far an attacker can move if one control fails.
Segmentation is moving from strategy to mainstream adoption
The Gartner® Hype Cycle™ for Zero-Trust Technology, 2026 identifies segmentation as one of the core tenets of Zero Trust. It rates network security microsegmentation as a High-benefit, early-mainstream technology, with 5% to 20% penetration of the target audience. Gartner also expects network microsegmentation to move toward the Plateau of Productivity within the next two years.
In our opinion, That maturity matters. It signals that microsegmentation is no longer only an emerging concept or isolated pilot. More organizations are evaluating how to apply granular, dynamic access policies between workloads, applications, and nodes across public, private, and hybrid cloud infrastructure.
The security case is clear: reduce the initial attack surface, limit lateral movement, and contain the impact of a breach. The operational path is less simple.
Why segmentation programs stall
Gartner calls out a handful of obstacles that will sound familiar to anyone running a segmentation program: complexity, lack of application dependency knowledge, legacy network firewalls, organizational dynamics, expense.
Underneath all of those is the same issue: enforcement is only one part of segmentation. Teams also need to understand how systems actually communicate today, define what access should look like, coordinate policy across different tools, and keep managing it as things change.
In a hybrid environment, one application path may cross a data center firewall, cloud security group, SASE control, and workload-level microsegmentation platform. If each control is managed independently, no team has a complete view of the path or a reliable way to prove that policy is consistent from end to end.
Start with risk, not the number of segments
A successful segmentation program should not aim to create the greatest possible number of zones. Gartner recommends selecting zones based on the highest risk and warns that oversegmentation is a leading cause of project failure and excessive cost.
That makes prioritization essential. Which applications are critical? Which vulnerabilities are reachable? Which paths could enable lateral movement into sensitive environments? Where would a policy change reduce the most exposure without introducing operational risk?
Answering those questions requires topology, application, vulnerability, and policy context, not a static inventory of rules.
Map dependencies before enforcing policy
Segmentation policy is only as accurate as the dependency information behind it. Unknown or incomplete application communication creates two bad outcomes: overly permissive policy that leaves attack paths open, or restrictive policy that breaks legitimate business services.
Teams need to see how applications communicate today, identify the valid paths, and understand which enforcement points govern each connection. That visibility gives security, network, cloud, and application teams a shared foundation for defining policy and reviewing change.
Plan for coexistence across traditional and modern controls
Microsegmentation does not replace every existing firewall or network control. Gartner recommends planning for coexistence and seeking approaches that integrate with traditional firewalls.
This is especially important for large enterprises. Segmentation may be enforced differently across on-premises networks, virtualized data centers, public cloud, containers, SASE, and cyber-physical environments. Zero Trust policy still needs to remain consistent, even when the underlying technologies are not.
A unified control plane can connect these enforcement layers. Instead of treating segmentation as a collection of separate configurations, teams can manage it as an enterprise policy: who or what should communicate, under what conditions, and with what evidence of compliance.
Automate change without giving up governance
Dynamic environments make manual segmentation difficult to sustain. New applications, cloud resources, and workloads appear faster than ticket-driven processes can safely accommodate. Gartner recommends automating microsegmentation deployment and changes, including integration with CI/CD workflows.
Automation should accelerate execution while preserving validation and accountability. Before a policy is implemented, teams should be able to model the path, assess risk, check compliance, identify the correct enforcement point, and route the change through the appropriate approval. After implementation, they should confirm that the intended access works, and that no unintended access was introduced.
How Tufin makes segmentation operational
Tufin enables segmentation and unifies policy control across hybrid, multi-vendor networks. It brings topology, path analysis, policy governance, risk context, and automated change into a centralized control plane.
With Tufin, organizations can:
- Visualize application connectivity and the enforcement points along each path
- Identify gaps, policy conflicts, and unintended exposure across segmentation boundaries
- Prioritize high-risk assets and zones before expanding enforcement
- Design, simulate, validate, and automate policy changes across network and cloud controls
- Continuously monitor segmentation posture and produce audit-ready evidence
This isn’t about forcing every segmentation control into one tool. It’s about giving teams shared visibility, governance, and change process across the tools they already have.
Build the Zero Trust control plane for what comes next
As Zero Trust expands across cloud, edge, cyber-physical systems, identity, and automation, segmentation will remain a critical line of defense. Its value is tangible: smaller attack surfaces, less lateral movement, and a reduced blast radius when prevention fails.
The organizations that succeed will treat segmentation as a continuously governed program, not a one-time architecture exercise. They will start with risk, map dependencies, coordinate traditional and modern controls, and automate change with policy guardrails built in.
Download the Gartner® Hype Cycle™ for Zero-Trust Technology, 2026 to explore the technologies shaping Zero Trust and the practical considerations for moving from strategy to adoption.
Gartner, Hype Cycle for Zero-Trust Technology, 2026, Thomas Lintemuth, Andrew Lerner, 21 July 2026.
Gartner and Hype Cycle are trademarks of Gartner, Inc., and/or its affiliates.
Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.
Ready to Learn More
Get a Demo