
- 01Brownfield programs that try to enforce least-privilege everywhere on day one almost always stall — undocumented dependencies and political cost dwarf the security benefit. Tier the estate.
- 02Four-tier brownfield: Tier 1 crown jewels (5–10%, full enforce + default deny), Tier 2 sensitive (20–30%, allowlist + alert on deviation), Tier 3 standard (40–50%, observation only), Tier 4 legacy (10–20%, isolated + scheduled for retirement).
- 03Discovery is the program — spend 60% of effort on flow visualization, app dependency mapping, and owner identification. Most tools include strong discovery; few customers actually use it for the months required to build a defensible policy.
- 04Expand from Tier 1 to Tier 2 only after Tier 1 has been stable in enforce for at least 60 days with zero severity-1 incidents traceable to policy. Patience pays back; haste produces the outage that ends the program.
Microsegmentation programs that try to enforce least-privilege everywhere east-west on day one almost always stall. The brownfield is full of undocumented dependencies, and the political cost of breaking them dwarfs the security benefit of locking them down.
The four-tier brownfield approach
- 01Tier 1 — Crown jewels (5–10% of workloads): full enforcement, default deny
- 02Tier 2 — Sensitive (20–30%): allowlist for known patterns, alert on deviations
- 03Tier 3 — Standard (40–50%): observation mode, no enforcement
- 04Tier 4 — Legacy (10–20%): isolated, monitored, scheduled for retirement
Discovery is the program
Spend 60% of program effort on discovery: flow visualization, application dependency mapping, owner identification. Most microsegmentation tools include strong discovery; few customers actually use it for the months required to build a defensible policy.
When to expand enforcement
Expand from Tier 1 to Tier 2 only after Tier 1 has been stable in enforce mode for at least 60 days with zero severity-1 incidents traceable to policy. Patience here pays back; haste produces an outage that ends the program.


