Back to Field Notes
Zero Trust Architecture/Field Note

Microsegmentation Without the Pain — A Brownfield Recipe

Microsegment what you must, monitor what you can. Trying to enforce zero-trust east-west everywhere kills the project.

Author

Sofia Reyes

Distinguished Architect, Zero Trust Practice

Published

January 28, 2026

Read

9 min

Share
AI-generated illustration of a banking facility
AI-generated illustration of a banking facility
Key Takeaways
  • 01Brownfield programs that try to enforce least-privilege everywhere on day one almost always stall — undocumented dependencies and political cost dwarf the security benefit. Tier the estate.
  • 02Four-tier brownfield: Tier 1 crown jewels (5–10%, full enforce + default deny), Tier 2 sensitive (20–30%, allowlist + alert on deviation), Tier 3 standard (40–50%, observation only), Tier 4 legacy (10–20%, isolated + scheduled for retirement).
  • 03Discovery is the program — spend 60% of effort on flow visualization, app dependency mapping, and owner identification. Most tools include strong discovery; few customers actually use it for the months required to build a defensible policy.
  • 04Expand from Tier 1 to Tier 2 only after Tier 1 has been stable in enforce for at least 60 days with zero severity-1 incidents traceable to policy. Patience pays back; haste produces the outage that ends the program.

Microsegmentation programs that try to enforce least-privilege everywhere east-west on day one almost always stall. The brownfield is full of undocumented dependencies, and the political cost of breaking them dwarfs the security benefit of locking them down.

The four-tier brownfield approach

  • 01Tier 1 — Crown jewels (5–10% of workloads): full enforcement, default deny
  • 02Tier 2 — Sensitive (20–30%): allowlist for known patterns, alert on deviations
  • 03Tier 3 — Standard (40–50%): observation mode, no enforcement
  • 04Tier 4 — Legacy (10–20%): isolated, monitored, scheduled for retirement

Discovery is the program

Spend 60% of program effort on discovery: flow visualization, application dependency mapping, owner identification. Most microsegmentation tools include strong discovery; few customers actually use it for the months required to build a defensible policy.

When to expand enforcement

Expand from Tier 1 to Tier 2 only after Tier 1 has been stable in enforce mode for at least 60 days with zero severity-1 incidents traceable to policy. Patience here pays back; haste produces an outage that ends the program.

#Microsegmentation#Network Security#Brownfield

/WRITTEN_BY

Sofia Reyes

Distinguished Architect, Zero Trust Practice · Alexa Cybersecurity